URLhaus Database

You are currently viewing the URLhaus database entry for https://blueglobalit.com/afterschool/schoolgirls.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:412314
URL: https://blueglobalit.com/afterschool/schoolgirls.php
URL Status:Offline
Host: blueglobalit.com
Date added:2020-07-13 07:26:05 UTC
Last online:2020-07-13 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-07-13 07:28:02 UTC to abusenoc{at}newcontinuum[dot]net)
Takedown time:2 hours, 44 minutes Good (down since 2020-07-13 10:12:12 UTC)
Tags:exe Gozi link ISFB link ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-13184vv53.exeexe dc54ff861a53ff7d8fef7c95159848006ad6cecf2661292d4b19020095a19627n/a 
2020-07-13577qqq9vv5d3.exeexe 20215dab4263b664cc5ed31450593815c31f8764cd681111dfbd42e0f465b3fen/a 
2020-07-13805vv53.exeexe 22628fb33229cd316816d95103e49b6393c5a069a4a0b2f5307084412a3ff6a4n/a 
2020-07-13369vv53.exeexe fa95bdc99dd6feb97baabb83636dbbc8a4ad8ff60095e0c1ba97e17d492c1453n/a 
2020-07-132468a107.exeexe 00dd547a489de10d2e856c8db2c44abb01cde1f7f63758a6da3cc2766f2e06b3n/a 
2020-07-132879a107.exeexe 0d1bc2e6577bae4da16fd4a43d2be88e720d52aaf250cbc1ebf24ccb15ef66b5n/a 
2020-07-132751a107.exeexe 3d9a62dc97b9d853feaf408e3dbb4b54190470feb85263a2824fce1d2af25611n/a 
2020-07-132720a107.exeexe d9cb63fd6170d5f3c59dd8e534c4b5c56a814fe533ba8e0ac3926764d264c922n/a 
2020-07-132988a107.exeexe 4fc6920a6520877b9fe8dcedeafc3899c8392b9af881acfab3b37ac75bf41524n/a 
2020-07-132826a107.exeexe 3b5610ae5a2b6266224b3ea7e0cd1085b4ccc8fab0c9cab58d9f2a14098cfbb2n/a 
2020-07-131820sase.exeexe d66c8587c97f9a2fd7a0552bbaafb282da33046f8e0248b4be965ce07b2fdc3an/a Gozi
2020-07-13766sase.exeexe 55ee6fa5f1c8f70b3279ed5f8686ab4cbb556b4f45d92b4167ee818f1e35f253n/a Gozi
2020-07-131095sase.exeexe 3abf0c9b2e61c02d37b214134a9ca3cd8ddabdb1280141481d96c43a9ef6a5f2n/a Gozi