URLhaus Database

You are currently viewing the URLhaus database entry for https://chinargoc.com/ea/autdenu which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2317931
URL: https://chinargoc.com/ea/autdenu
URL Status:Offline
Host: chinargoc.com
Date added:2022-09-28 17:46:18 UTC
Last online:2022-10-19 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 23:39:07 UTC to abuse{at}hostgator[dot]com)
Takedown time:20 days, 6 hours, 9 minutes Bad (down since 2022-10-19 05:48:19 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-13gwuRCgsZQiu.zipunknown 004c33061e237f3ed77921e9d1ba6cca31457dce9750b2b9cf936d1b6b8dfcd8n/a 
2022-10-09Co2291439769.zipzip e5d74aa74f8473315283cdf06c3d18105c015860cf48d960ffd6421be5a9e374Virustotal results 50.77% Quakbot
2022-10-06Co2523195918.zipzip 04d8fc08fdbcab139421eddab0cb6d475c72ec45846030c9259ef2c303ee5c90n/a Quakbot
2022-10-02C3053393551.zipzip 26dda080d016a98e4a978c1c6d2dfc9a2950d2ab55c0a166ae9367c2f7ed5ae0Virustotal results 1.59% 
2022-09-30P2173475963.zipzip 37130c6d76f50f7ab59953874e8b888653549d6d81365db8da211e909e0fcfa1n/a 
2022-09-29Gall3101754796.zipzip 9d898d1cde4a11d1d8788bad96447e01d0efd153c6d59896541792e5d51d2985Virustotal results 1.59% 
2022-09-29Gall3750700281.zipzip b31d2190d96759a7b6d698528fdd20640ffb6afab9818236f037f2198a7b00d5Virustotal results 1.59% 
2022-09-28G2353825290.zipzip 8a0c2eeea77c8eb087a4c0528ac254cf217c6978d8ae38428ffa886c12ca441en/a