URLhaus Database

You are currently viewing the URLhaus database entry for https://www.graficadupress.com.br/catalog/model/amazon/images/wam.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2252498
URL: https://www.graficadupress.com.br/catalog/model/amazon/images/wam.exe
URL Status:Offline
Host: www.graficadupress.com.br
Date added:2022-06-29 16:54:05 UTC
Last online:2022-09-30 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-29 16:55:14 UTC to abuse{at}matrix[dot]com[dot]br)
Takedown time:3 months, 2 days, 19 hours, 36 minutes Bad (down since 2022-09-30 12:32:00 UTC)
Tags:32 exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-02n/aexe 4453055e024007f41d02ce67aa9294650f27c1b681ec486016133439cce9891cn/a 
2022-07-01n/aexe a9cee4cca45ae0edd47901ed683c16e6230da1577621036d0007b8b738a4ce9dn/a 
2022-07-01n/aexe 0343878e8cf4bd74fc8dea656b436340dcbbf572b4c91d20744049d9f5156cd8n/a 
2022-07-01n/aexe c6b0165d835a43163047923e9dae67fa447c1a1c7049b65275ec5823ba195557n/a 
2022-07-01n/aexe 99f6c5b1e98a53e570aa0992a7d48b639e6547e4c81a4bad2242b5e4734747ban/a 
2022-06-30n/aexe cd537176ba1fb5a6936bc0d81355b393a203a4b794950d81d9b8f994736aed29n/a 
2022-06-30n/aexe be1d91508db360f096b35144aef301b038330bef3e7f7f197018cb92403c0397n/a 
2022-06-29n/aexe 4f838e78d6ee90470bf23ff8755cf8d81ed281f314bda8a901329a1a08f72b30Virustotal results 23.88%
2022-06-29n/aexe ec58fa2d1346060279ee99733d74491fd84964e469fc29973b220915eab5d168Virustotal results 29.41%RedLineStealer