URLhaus Database

You are currently viewing the URLhaus database entry for http://granportale.com.br/img/nel.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:141742
URL: http://granportale.com.br/img/nel.jpg
URL Status:Offline
Host: granportale.com.br
Date added:2019-02-21 11:23:48 UTC
Last online:2020-05-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-02-21 11:24:02 UTC to abuso{at}guzzo[dot]com[dot]br)
Takedown time:1 year, 3 month, 10 days, 8 hours, 37 minutes Bad (down since 2020-05-26 20:01:18 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-25n/aexe 227835a4926bb09eef18194a27f70c977b3124a8924024c01773da8e52f1322dn/a 
2020-01-09n/aexe 8bbee9db188db8518e807b7f319e59b8835d3bb5d6bf1986ccf3c431caaf46c9n/a 
2019-12-27n/aexe ed0f15180c39f188e3ee25f758499e55340e7e9b44b86ad2336ffc5611293fc8n/a 
2019-08-17n/aexe 8a1cfe6606b18ee542306918bd0b94a35a3ada3cef88550fdd04f37ab62e9f9cn/a 
2019-06-05n/aexe cd35358335d525968db20f7e44c3dd74a9485320b7c83befcf699ebbae8f09a3n/a 
2019-02-21n/aexe 83b3488388ed6be7a0376af0772c8d12e89bf742f2395bdb44eed1503fb0cfe2Virustotal results 45.59% AgentTesla