URLhaus Database

You are currently viewing the URLhaus database entry for http://granportale.com.br/img/cryptedclient.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:171429
URL: http://granportale.com.br/img/cryptedclient.exe
URL Status:Offline
Host: granportale.com.br
Date added:2019-04-04 14:28:18 UTC
Last online:2020-05-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-04-04 14:30:03 UTC to abuso{at}guzzo[dot]com[dot]br)
Takedown time:1 year, 1 month, 28 days, 5 hours, 31 minutes Bad (down since 2020-05-26 20:01:19 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-25n/aexe 46aca6a4102cabb64b407ab504ff7328ccb1702caef3194bf4bbb99ece416853n/a 
2020-05-20n/aexe d6f74e60d4736d58322c1c9f8a7da1994838cb0fa3ddfafe923b068cdf02139cn/a 
2020-05-15n/aexe 81c06d024d73439bbfd8e25d43d7f6fb71efd3f6ab6f3aa833a33f518a5fd7b4n/a 
2020-05-04n/aexe 97e6b28803a8bd29e626e48d141868949770c42151686d371f456a25d9c192fdn/a 
2019-11-25n/aexe 081f3657a19fc26f4057bcc463d8fac6e3e18873528d00c6c984112afa57ecc0n/a 
2019-08-20n/aexe 3d9dde80789ba931f10b146fd0b00dc65b58101f8bb3271373549c538cb89d79n/a 
2019-04-12n/aexe 50454e5620931844e369ad4a9d3a772f956856399e5f6bf79a0956aa1e530560n/a 
2019-04-04n/aexe e4548351774f583e060d3ed8b153e31f0afe889c9c5aee95f393fe4b1f591755Virustotal results 34.38%