URLhaus Database

You are currently viewing the URLhaus database entry for https://qurioso.biztunai.com/jwejlks1y.tar which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1674022
URL: https://qurioso.biztunai.com/jwejlks1y.tar
URL Status:Offline
Host: qurioso.biztunai.com
Date added:2021-10-13 13:14:35 UTC
Last online:2021-10-14 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2021-10-13 13:18:08 UTC to abuse{at}webserver[dot]com[dot]my)
Takedown time:13 hours, 56 minutes Good (down since 2021-10-14 03:14:31 UTC)
Tags:Dridex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-13n/adll 8fe3489f653ab546ca454869e83b3046518af57b084095dbaf9c8ee04bcb9adbn/a Dridex
2021-10-13n/adll 766542a60130833040c1a8c18168cb83a6777b5de0e3516b34b2fbb8b50894ccVirustotal results 10.77% Dridex
2021-10-13n/adll ff0b0878821718f9f9626ee6f60ac6268f9a3c529f18cacf485236767f249f23n/aDridex
2021-10-13n/adll 7ab24453e040b90ec8d8389737ca6968a35ec24a28e494b97eb9eb770c90e8b2Virustotal results 12.00% Dridex
2021-10-13n/adll a2d5bac98e9a03d02157521b1ae760fc6ce3a5760a1ab83b18bd37403f01cbbcn/a Dridex
2021-10-13n/adll 631522e561705d7b1e8943b61927aff2be4325cca41ee5458b6180793acb9de0n/a Dridex
2021-10-13n/adll 88a94091ec39cf0fcb60f326e81f2a12ac40c6f41072f04dd0088d9c435e2d31n/aDridex
2021-10-13n/adll 99dfcde4f61579e52164bee9c1078b50f84c8246d86c68ff0c8352df88032d66n/a Dridex