URLhaus Database

You are currently viewing the URLhaus database entry for http://onholyland.com/HAY/OSE.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:217599
URL: http://onholyland.com/HAY/OSE.exe
URL Status:Offline
Host: onholyland.com
Date added:2019-07-17 17:33:13 UTC
Last online:2019-07-24 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-07-17 17:34:04 UTC to abuse{at}cloudwm[dot]com)
Takedown time:6 days, 7 hours, 40 minutes Bad (down since 2019-07-24 01:14:19 UTC)
Tags:exe NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-07-23n/aexe ccc03457a3d6bb862d68fdee3102c686c9e2eeac295beea92616b44010972cd2n/a NanoCore
2019-07-22n/aexe ac7d724e9bbf3ccdfbfaf124ef79a633406e7c10a7fe72804ebab1d544066da3n/a NanoCore
2019-07-21n/aexe d7273c3badf7d34694a65dcf4a7af1952b9e1d018d15e609bb7bb40332dfeba3n/a NanoCore
2019-07-19n/aexe 81da7e20196d1e10716e950e6b950e90c6f169199d6e7b924bb194cc0aa0c441Virustotal results 21.43% NanoCore
2019-07-19n/aexe a70f76baef6a68aeab796ce1991af3214280a68705fda45fd8aa3b1cb2a1ec8eVirustotal results 19.70% NanoCore
2019-07-17n/aexe 99018a7e4cfbe508cbd2cb327b0b1caec542eeff1fb35ba9ae81d2420b31f34bn/a NanoCore
2019-07-17n/aexe 29113096fcedc65703308b0725a15b3abb4bcd9dde683a8b738538bb4332511dVirustotal results 28.99% NanoCore