URLhaus Database

You are currently viewing the URLhaus database entry for http://granportale.com.br/img/prince.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:141703
URL: http://granportale.com.br/img/prince.jpg
URL Status:Offline
Host: granportale.com.br
Date added:2019-02-21 10:43:07 UTC
Last online:2020-05-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-02-21 10:44:02 UTC to abuso{at}guzzo[dot]com[dot]br)
Takedown time:1 year, 3 month, 10 days, 9 hours, 17 minutes Bad (down since 2020-05-26 20:01:18 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-13n/aexe a7f224296111030e505f12951cca6c1cf1940ba1e2a3ff32c54d32cb4406ba28n/a 
2019-12-27n/aexe 39917fc358043680ba0a9c3c7ead860d36fecc364cac3f72037c3568445b6bccn/a 
2019-12-11n/aexe 17c62c64c5f389a15824bca8824453e320eb8b968a50b054570facab691ebddfn/a 
2019-08-18n/aexe 89888d7476a913b6e3d7f369fe4b5494c8e7c6ae7789946dbbb54b93ec852880n/a 
2019-08-17n/aexe 5138dceb682592fb5954e89c8741bbdfbcb4aeea5f184670fa5e11985effe9bfn/a 
2019-08-17n/aexe 9e6f08234bd40addd9d579d7b7c75c39282a556e46185448e759cc9092e7dfd1n/a 
2019-06-05n/aexe 28f9bc298f1f57cfb07108e427cad105d21fdeeb295d17881175af1f4f273f2fn/a 
2019-02-21n/aexe e3afb8be8f04e148a4214c375eff4817f2afcfcaff0f6a0bf2f5e324d9649b1bVirustotal results 63.38%AgentTesla