URLhaus Database

You are currently viewing the URLhaus database entry for http://diegogrimblat.com/flv/Ojn4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178680
URL: http://diegogrimblat.com/flv/Ojn4/
URL Status:Offline
Host: diegogrimblat.com
Date added:2019-04-16 13:08:13 UTC
Last online:2019-04-27 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 13:10:04 UTC to abuse{at}ovh[dot]net)
Takedown time:10 days, 15 hours, 35 minutes Bad (down since 2019-04-27 04:45:40 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-18Q8ot6K5RnQ.exeexe 1b6aa692ba88e13ddec659e9c601d305146fba99e16181467cdfe49c7b109918Virustotal results 18.18% Heodo
2019-04-17sEmNRT0G.exeexe 8563ecda0a46762d82674a0381e1bc99b8518cbb54691ad0b294c44a5e2074a0n/a Heodo
2019-04-17O4Uek79o.exeexe fe7f3c4e834e67b455d62b5ddfdfbe27acf699641e163038e4e320c310f44ae0Virustotal results 30.43% Heodo
2019-04-17QdSROwfWxHB4.exeexe ac9915fc4b0a1fdc1a853e119d0508e290952d43ee16e0abae3cff26c2ed6471Virustotal results 28.36% Heodo
2019-04-17foo1F2qkRi.exeexe 06b0aacfa0b6ec7017e1ade64a4bfdc0a8d76fc74772835dd44134b40833b9fbVirustotal results 30.00% Heodo
2019-04-17rFV01LXchb.exeexe 50843f1c34dbe3de77a86615f7cc0064ebdabca83d2248dae7b93fbf8c7bb80eVirustotal results 39.73% Heodo
2019-04-17ZpgKtRT0.exeexe cabd6a707a679f24d05dc9017033592b7edefb0d4ff28ab374db176c5488ca42Virustotal results 10.61% Heodo
2019-04-17DlnyJMeDynGh.exeexe f349869e1e5d51c932e1645562ba7bfe325faea0f049e81703325207c71103beVirustotal results 37.14% Heodo
2019-04-17odvQe1sVrvPr.exeexe 93b93039ce9dc42388d55736d19e5d8e6393012acbb547e5486d5934c38ac292Virustotal results 33.33% Heodo
2019-04-17p7tasOYIfELV.exeexe 94eed97bc2cc503578779d50643a04a08d28055cca96ff8800086b36542840ben/a Heodo
2019-04-17lBxBlrjXBYL.exeexe 0106fad7a1ceb64a7d2ebed424ce86d979ac976cb352326c0fca9c7d0ac5330fVirustotal results 36.62% Heodo
2019-04-17jqUsXUdtB.exeexe 28f7eaad2f3063e93a532fff5eb8eeed63557ee720d44d0f17334d26007564faVirustotal results 36.62% Heodo
2019-04-17OM4N66l9.exeexe bec4bdfdbf87f89b315837db5e0c3922cd167d1e47407106b6702fbe9f54ef90Virustotal results 31.88% Heodo
2019-04-17EcXhYPJl.exeexe 478968aeea42221e0c760a811af1560eeaa6489b77cdf69b4ae3763c59e60be0n/a Heodo
2019-04-17Ntw9R8GZ1U6.exeexe 7206e9d4302bf1c8ecd0fb33cec5350621ef1233d383de6ddeac15be4d574defVirustotal results 36.62% Heodo
2019-04-17eHNo4qQRUCk.exeexe 48900a85a1a4afcf216ea9912176bb20edab059d1bb27d02caa6fbbcc060d35eVirustotal results 32.84% Heodo
2019-04-17CmRSYSJx.exeexe d57df21783413fdba7fcf694481bffdb24c68d5f6e74b64337dba599f4d4c375n/a Heodo
2019-04-162CtOIcrby.exeexe 42d5b442bcba882b9b67d483d983812918c8f16bf244617e5125e54ed39c45b4Virustotal results 10.61% Heodo
2019-04-16XoPdVQrPVH.exeexe 4015b2182a198d775500fdb03aa57a82906d72c72c4066af16764478721c889dVirustotal results 26.15% Heodo
2019-04-16mBWOCYbdNOWD.exeexe db70e564ea79a94f5fa4be36192be286a096f31c45b21c0d9b04cbb41d42e117Virustotal results 27.27% Heodo
2019-04-16EKtaGS72PyqN.exeexe c3da3d50a58b61da152ef9324924304bba6ab3b0485140120dd2ae9f6e9a11c1n/a Heodo
2019-04-16KuGfn5vQfCz.exeexe d41ecd67cd6ce7e26a4ad38afa7ce3a91ee198443cd1cd59c65c94f159c80f91Virustotal results 31.43% Heodo
2019-04-16zVYU9rq2wowG.exeexe c481b71e426986b974b3b8a3438ed20e02acceb15e3cef087df32ee7663f34f5n/a Heodo
2019-04-16xys98p00.exeexe 4bba21068231dfd43232ff7dc61e0a7fb17195c86b4acebcf0bc395e24fe9a94n/a Heodo