URLhaus Database

You are currently viewing the URLhaus database entry for http://perbrynildsen.no/msg.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:147456
URL: http://perbrynildsen.no/msg.jpg
URL Status:Offline
Host: perbrynildsen.no
Date added:2019-02-26 09:43:24 UTC
Last online:2019-04-09 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2019-02-26 09:44:09 UTC to abuse{at}servage[dot]net)
Takedown time:1 month, 11 days, 15 hours, 59 minutes Bad (down since 2019-04-09 01:43:26 UTC)
Tags:exe RUS Troldesh link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-29n/aexe f34412301a6fde6ba09b3f654c4845cbd7b3930c57e00fd76e764d664edb01ean/a 
2019-03-26n/aexe 6e8a8377fc248d658d5025a64ae54f03046c7b86ced48d35f059b4289da66942n/a 
2019-02-28n/aexe ead11d8976faa6085704d59b3b0ec80f5c084cfa3c585031748c53b612876692n/a 
2019-02-26n/aexe 701d3db21920f78b8ed2eb6b4286f858277928f50d567c9c6594bd1971e9c07eVirustotal results 30.77%Ransomware.Troldesh