URLhaus Database

You are currently viewing the URLhaus database entry for http://onholyland.com/LUC/PPC.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:221608
URL: http://onholyland.com/LUC/PPC.exe
URL Status:Offline
Host: onholyland.com
Date added:2019-08-01 23:52:06 UTC
Last online:2019-08-11 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2019-08-01 23:54:03 UTC to abuse{at}cloudwm[dot]com)
Takedown time:9 days, 12 hours, 4 minutes Bad (down since 2019-08-11 11:58:15 UTC)
Tags:exe NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-08-09n/aexe cb3c7822c0200e90b47fcd6682918a68a329405e1f7a505bd723a98e8a5521b7n/a 
2019-08-08n/aexe 1ffd517b997feb9255b829931e0c78758961e54e4949894f4ced6683e5a92f3dn/a NanoCore
2019-08-08n/aexe 8ac3b548a5849e1f252eb7aa696801e2c7ac57789b7d1e1cae0f1fdac0728f51n/a NanoCore
2019-08-07n/aexe 72450390fd29b8357a21936c228b909dc9b47ea10fe511fea08640da9c6a8815n/a NanoCore
2019-08-06n/aexe 839f3e04e5723d54e87f75d6f8847318d99583ef75642fef6a37c8bcafe52051n/a NanoCore
2019-08-05n/aexe 51b8d00c34dfa64ef5638cb85e12ee27fc9245178a31e374c43950bb7d716f51n/a NanoCore
2019-08-05n/aexe 9f41a5a3cebd9aaf315fe540289f809722fec42a109816636e75c4034b428143n/a NanoCore
2019-08-01n/aexe 9c9b967aa1f644c8a3d61bcbc708c89235fd84ef7b5040127f9a975241dda722Virustotal results 44.44% NanoCore