URLhaus Database

You are currently viewing the URLhaus database entry for http://greencolb.com/DOC/decku.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:77725
URL: http://greencolb.com/DOC/decku.exe
URL Status:Offline
Host: greencolb.com
Date added:2018-11-09 06:38:10 UTC
Last online:2018-11-19 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-11-09 06:40:02 UTC to abuse{at}unifiedlayer[dot]com)
Takedown time:10 days, 15 hours, 28 minutes Bad (down since 2018-11-19 22:08:36 UTC)
Tags:exe HawkEye link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-19n/aexe 76cda3c8048337d1b0bfc9f4be2b3b9777e1a8c93a48f7e10b375d8f9f764b40Virustotal results 10.29% 
2018-11-11n/aexe 85be7b17e9c05176101d0dcf45bca6c6e6602ec4e5dd5be852e82262905ca0d2n/a HawkEye
2018-11-09n/aexe 76b88f2530ec43237e12697e6207b65ffdc65cbaf9d8b82d4ff001d04a9a1322Virustotal results 17.91% HawkEye