URLhaus Database

You are currently viewing the URLhaus database entry for http://greensync.com.br/aspnet_clientOld/ohGq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:496749
URL: http://greensync.com.br/aspnet_clientOld/ohGq/
URL Status:Offline
Host: greensync.com.br
Date added:2020-09-14 14:08:08 UTC
Last online:2020-09-14 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 14:11:47 UTC to abuse{at}hospedagem[dot]net)
Takedown time:5 hours, 0 minutes Good (down since 2020-09-14 19:12:06 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14oLGTMylKbzzxPXzWl.exeexe 1a4cca935a8290c993ff4987aa8a3e9343daa52324418a94cfad60c566a97d53n/a Heodo
2020-09-14tYNITloWAvLP.exeexe cad359c3b8ed1925a52894a54acba23284b56de2d539ba305b84395586f32a8bn/a Heodo
2020-09-14VkEqo.exeexe 845e8e0064e9140914f4a1b395579697ab47d63963e375f9450f3a0657675987n/a Heodo
2020-09-14Gf9QvZBNZozCVvdTrqM1.exeexe 4f10a6cd08984d989fe29e785c0f0e91b9d49355e8d4842a679deb58e29627e5n/a Heodo
2020-09-14kVlyEhti2.exeexe 6223189453423398bae5ad762484b760b1cff79b8df683294df54e537931dec5n/a Heodo
2020-09-14bBp9KOFo.exeexe debf12696a9fac774d68b7fc251f0ccb8738da3530604495db72538adf21eb4cn/a Heodo
2020-09-142HzXpNyTHFzdbicUO2.exeexe af91c87c0e1e6960884863eb09f8623e9c743a35d38fb75d2788cd1bd4fd2ed3n/a Heodo
2020-09-14KKqhYBERKtvK1rm9T.exeexe 96fda7ad305ee42126c20a7ba12b7670a7faeec0150662d13ee7cf64cae98909n/a Heodo
2020-09-14ifzy.exeexe 33a4274ea9821bf350e656b5c20cd92930655c99fdaf4a3e7edb3fe338df3c54n/a Heodo
2020-09-14DD3LPiJuBMfgkfgk.exeexe 9be6ce2f58729664863e65136f1792d44f97763ec061eac11a52965f3a2c9f85n/a Heodo
2020-09-146t7HVUkHNZxut.exeexe 24bfd4f40757418de2466fae8202d1bd451039e989eaa1be05996e1150890c99n/a Heodo
2020-09-14yMmHsMMyGjrrxvPyG9.exeexe b75027240ecb466ff351080911e9c7d2d411624cd82ac64b9c03843fedd31646n/a Heodo
2020-09-14XE6Q.exeexe a2e5d562a960642a7ea92979f4c3e7ebebfca664ab89bdde7ee073d69c3e398cn/a Heodo