URLhaus Database

You are currently viewing the URLhaus database entry for http://ceoseguros.com/css/a.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:78298
URL: http://ceoseguros.com/css/a.jpg
URL Status:Offline
Host: ceoseguros.com
Date added:2018-11-10 22:09:16 UTC
Last online:2018-12-18 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: de_aviation
Abuse complaint sent (?): Yes (2018-11-10 22:10:04 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 month, 7 days, 18 hours, 31 minutes Bad (down since 2018-12-18 16:41:21 UTC)
Tags:exe Imminent link ImminentRAT link rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-18n/aexe c068d24a8c47c38eaf5211d74c85b0b844d5af259a92e88f7d0cf8ba391328bdn/a ImminentRAT
2018-12-17n/aexe 6ea23458ec64592f0adf578c180970f831411fbca56b35dc4d987460913c4a29n/a ImminentRAT
2018-12-13n/aexe a6c95e771513a1d8566efe3ed259cdbebc97d1d88345dd4111064f51b2c39e35n/a 
2018-11-19n/aexe fd15068c26f74a47f6a695c76d53553a92d3e729e83b7723f40906ea1c87d37bn/a ImminentRAT
2018-11-14n/aexe 8183b5c172230f6583f0c9f1294ab62907d7e92dd414f1f997ba74f54885c56fn/a ImminentRAT
2018-11-10n/aexe bb74ec9cea757308df5dbdd8d9af3249f6250ef26ed3c4e1a149c787e469c464n/a ImminentRAT