URLhaus Database

You are currently viewing the URLhaus database entry for http://granportale.com.br/img/cryptedkalu.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:171425
URL: http://granportale.com.br/img/cryptedkalu.exe
URL Status:Offline
Host: granportale.com.br
Date added:2019-04-04 14:23:14 UTC
Last online:2020-05-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-04-04 14:24:02 UTC to abuso{at}guzzo[dot]com[dot]br)
Takedown time:1 year, 1 month, 28 days, 5 hours, 37 minutes Bad (down since 2020-05-26 20:01:19 UTC)
Tags:exe Pony link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-25n/aexe 62b9da0c541383cfa588f54789e4629025b2cb047bfaf76c4ae539da3a5029ffn/a 
2019-12-17n/aexe 5df9bf09cd694c5a1e1ee82e16b7c836aee4b34662c158d99adcb27fc473c7aan/a 
2019-11-25n/aexe 53abf543dd70a61b245ce9122816accafc3db8595083a4bad8aaaeb7e0c33041n/a 
2019-04-09n/aexe a4a662af9b67e69da78ea30298d8e7465489e720d613f76d014f23420e670c35n/a 
2019-04-04n/aexe 703ca6f756d1a196c376685adf22dc751b5fd9bfda791c81130a135a9a81789cVirustotal results 33.33% Downloader.Pony