URLhaus Database

You are currently viewing the URLhaus database entry for http://granportale.com.br/projetos/2w80oLSMws3d.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:171433
URL: http://granportale.com.br/projetos/2w80oLSMws3d.exe
URL Status:Offline
Host: granportale.com.br
Date added:2019-04-04 14:40:07 UTC
Last online:2020-05-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-04-04 14:42:02 UTC to abuso{at}guzzo[dot]com[dot]br)
Takedown time:1 year, 1 month, 28 days, 5 hours, 19 minutes Bad (down since 2020-05-26 20:01:19 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-23n/aexe 9ce6958b8b5e5564eae60700f84bc813fc7547f8a520e7dada38811b6abbad19n/a 
2020-04-13n/aexe beaf3ce1c7a7406c78ba0d73f593d58e21a7b6ea426b44cc0e9ee28dc4ae9109n/a 
2020-04-12n/aexe 97d29cb3d9acaccb90f8abc8b087718a9a2b0efe83de20a7a4c75b2542b8baf6n/a 
2020-04-07n/aexe 7e10b382d2aa47606104651639f5fea9f79201bec04558fad010db1f7d1e1ab5n/a 
2019-06-06n/aexe 0b5c7741bef400d5d812f551f0ba32bf2405e9e9e9343e398b8999444878d37cn/a 
2019-04-12n/aexe 45db1139864ca8ec36666d47bcbfacf4212924fa80ac62ed94bbc55db57874aan/a 
2019-04-09n/aexe 4bc25479eba257fba7e624f5d53c72f659afa35cd2d97aad816a4559123626b4n/a 
2019-04-04n/aexe 5bf722cadb29b531d483c868e579abbedefa9ae90e8e59d3c19ff71792bbf295Virustotal results 29.03% AgentTesla