URLhaus Database

You are currently viewing the URLhaus database entry for https://segorganizacao.com/tae/atidllimio which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2148091
URL: https://segorganizacao.com/tae/atidllimio
URL Status:Offline
Host: segorganizacao.com
Date added:2022-04-14 14:04:27 UTC
Last online:2022-04-16 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2022-04-14 16:16:12 UTC to abuse{at}liquidweb[dot]com,abuse{at}nexcess[dot]net)
Takedown time:1 day, 8 hours, 18 minutes Poor (down since 2022-04-16 00:34:52 UTC)
Tags:Qakbot link qbot link Quakbot link TR

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-15atidllimio.zipzip 3db75f8848e0b0d09db42ea1e181bfc95c1a004b92ed7360032d6ad216a63581Virustotal results 14.29% Quakbot
2022-04-15atidllimio.zipzip ba5c3431611c794e44ab689ff515ab683f7bc940a8270095683e190a8abb1c70Virustotal results 22.41% Quakbot
2022-04-15atidllimio.zipzip 40a22c80fa4c14c8ffcaa05017612c80f62f6ffe67f5c620f2a9a86bfd1f19fcVirustotal results 30.65% Quakbot
2022-04-14atidllimio.zipzip 82f2aa3daf4e97f702bd9b550a4a9434e53e22df807d403a61d5e1cccce0442fn/a Quakbot