URLhaus Database

You are currently viewing the URLhaus database entry for http://gothw.club/jshp1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:407605
URL: http://gothw.club/jshp1.exe
URL Status:Offline
Host: gothw.club
Date added:2020-07-04 05:58:06 UTC
Last online:2020-07-10 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2020-07-10 10:42:02 UTC to abuse{at}server-panel[dot]net)
Takedown time:13 days, 12 hours, 4 minutes Bad (down since 2020-07-17 17:48:47 UTC)
Tags:AgentTesla link ArkeiStealer link exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-16n/aexe b6dd373190a7147e7ce0ddfe98148bdbb5683a9bb67ecb6dc6a92b3be001ad22n/a 
2020-07-16n/aexe 176fe1d16b96d5727bf2853d103c3acf7a12e137ae69da815d154c1ecfafb0fan/a 
2020-07-15n/aexe 495a5bcf2a48e0674f75772b90ae6701d5f7d776b2fd7347d4f415b1a2e05299Virustotal results 20.83% 
2020-07-15n/aexe a85cd89c706de58c539bc3cd8f272afde7a1f6a1c195d6b6d97f3df433c6f905n/a 
2020-07-14n/aexe 3430545ed9a82246bbc4f866b67a7028be58df349a705ce2b5df74c72c3b4642n/a 
2020-07-13n/aexe 72d5d00a656a83ada587e55d3a3ed0164e57448e723561ffbc6b8445d7f00898n/a 
2020-07-13n/aexe 42791a7bbdeeb8f610488d3dc8d2ada81b9fc048fc128ff8c926ee0d9f7a110cn/a 
2020-07-12n/aexe 21d7514ffec0e458d2edb4a864c699a6958b44881d53028c3dd94dd8dc5f31a2n/a 
2020-07-12n/aexe 7a49dbce30ac04b950128d383b2b6f375f291542755e5100643c55aeb4ea6083n/a 
2020-07-12n/aexe 6edfc1121f797eb10daa3059a1d996215218c85db358fe9b54f0cb7b2deac8b9n/a 
2020-07-10n/aexe f208226c60c95ee10f879f0f38ad9bf85a30fa411d6d20893e9ddaea5a0daf20n/a 
2020-07-10n/aexe 9b480eba8c66042041b18c29afdef1cd22857a0c24aee0afed8a3fa4ef93b955Virustotal results 22.54% 
2020-07-10n/aexe ee5330d0a01cd004994c5798a3c0c09b160b560e6cdb3f2509b9af2431a0a8fdn/aRedLineStealer
2020-07-10n/aexe 418b130f5c73961c34d1ec03208f0c9393c222beedd2164d6e8de02c9cc43799n/a 
2020-07-09n/aexe a637d8d9ee6ac3ebb068888282dc23e228432dc239ce23e8791516ffd8bdf58cn/a 
2020-07-09n/aexe afdd4c38c1245db142a7de2367c60f7a0b07103b9947adddd85286097ae42aa5n/a 
2020-07-09n/aexe f0831b0ebc963c0d8dfdbcd780a520eab25577db8c5aca7f7076f8ef1a451fafn/a 
2020-07-09n/aexe 4a2b9ab0a784e4f1f6b86fb3c9db0a91c74dc9966c6c5cae0ba486c27215c639n/a 1xxbot
2020-07-09n/aexe ca3822a6d626b64ac7ed5f699c30758a27eebe60a0d72598155558a40a8297f9n/a 
2020-07-09n/aexe 4d42dfe7906c2a1c3b72e17b82c040ff7fecb6f317757cf8ecc59c67e7c8d7b1n/a 
2020-07-08n/aexe df54c4cf12eb9ff00568d4936f2c55a3193f6726b1a7f59c78a88a6f06488dbdn/a
2020-07-08n/aexe ce132385429d155c07133450ef659e09f5fdfde333113a4f1ade379b9962b7fbVirustotal results 39.44% 
2020-07-08n/aexe 3ee692779441b3a14699edc0f9ad269c58281d5735c570a9468f077739db26ddn/aRedLineStealer
2020-07-07n/aexe 1ca0fa0599ad3337700cfe55be2f6d0462a7e4301f8ccfdd87167a66754e7e71n/a
2020-07-07n/aexe 83d8450c54c541ddceff68e7949b8709dfd557a79a4134d8434ca97df221de0en/a 
2020-07-07n/aexe de82af11b87869dfecdeac8a0a204ef51ec2ae52fca6230c6745ff2a09985c3en/a 
2020-07-07n/aexe de82af11b87869dfecdeac8a0a204ef51ec2ae52fca6230c6745ff2a09985c3en/a 
2020-07-07n/aexe 4770c737ec585b1891363820395a57698b7ff37ee57bb6748ee97eacc337bd1cn/a 
2020-07-07n/aexe dbbc9e640af23658de56eba2f5ec2152de38fa35f11343f0d2216b8b5d7967a8n/aRedLineStealer
2020-07-06n/aexe 8d377cfc96a5f8e67df1ebcedd7bcb322beba89b0a95c8cfc02b203b08ea3bb8n/a 
2020-07-06n/aexe db76b13a6ba32f1cc5c6e23705957b627ab9ff18286c2138317c2ec4507ff07en/a 
2020-07-06n/aexe f37537ab1a0c2fd830bf2ea03f299ceccf2d1eb5f8c72be80580a680450da4aaVirustotal results 8.57%RedLineStealer
2020-07-05n/aexe 0b95b126cf983c7a26829e8355d66de10cc1e085a3a981703040269ce43f863an/aAgentTesla
2020-07-05n/aexe 658ab92e6f2e0e0b2ca141b3531d33d0e7f3511e35fa54541e954b4d88371afdn/a 
2020-07-05n/aexe 24c871a763e208ba82f7ce7df48fea42c962214954181dc72f17c9112cc74c5en/aAgentTesla
2020-07-04n/aexe e363126219327414e0ab73a7b053e3c25bcfd656ff7b3b1f5db6e86076a93986n/aAgentTesla
2020-07-04n/aexe 05a155b2e1218708d1803e647ce21abb556abb208d16c7861904f5ea938bde03n/aAgentTesla
2020-07-04n/aexe 033741ca568e4e71a586be960e503415579b0520d2c9ecd298ed03becf406b9cn/aArkeiStealer
2020-07-04n/aexe 256966058fb63c734b270b6842820287bb83a5895d0a14a5b66f52db037405fbn/aAgentTesla