URLhaus Database

You are currently viewing the URLhaus database entry for https://forzzagym.com.mx/tuag/eaomiseuallmrbot which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2318791
URL: https://forzzagym.com.mx/tuag/eaomiseuallmrbot
URL Status:Offline
Host: forzzagym.com.mx
Date added:2022-09-28 17:54:09 UTC
Last online:2022-11-23 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-05 02:02:10 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 month, 25 days, 17 hours, 38 minutes Bad (down since 2022-11-23 11:33:57 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-25FpawSEqzLRmgWZbVDKK.zipunknown ab84aeb92147828f70323579bcc60bf6f0b2fa221581c3f3061d2a3936fb2689n/a 
2022-10-19obOjHLFuN.zipunknown ad370cc37785f3bbf0ddd1cf79e7d43568b5ead19b325adff56c128f06c36889n/a 
2022-10-14nPPenYcOflglN.zipunknown 3541aab7c832fbe5b55575ce81dcbad6cb44881a6db094db6a08b2e7eeb74477n/a 
2022-10-08Repellattempore3601555757.zipzip 14f0a6c9c78092a65a0066f8d71987508c27745ebdd1d08a14569e4a86e2d098Virustotal results 43.94% Quakbot
2022-10-06G661032511.zipzip 9aa4382753dc68368674eaa43959b95afdc172155c80673381f3bf89ccb86d56Virustotal results 19.70% Quakbot
2022-10-05Co1067412303.zipzip 2d0b4635d9a965cfecfeb1cdd1022aa95e813b929c3572c2ea29fb2b8ba0a897n/a Quakbot
2022-10-01CA2633082648.zipzip fa0c7e00a0ac787e3c98115f1ea275aaacff225e1de71c1876f74b7872965071n/a 
2022-09-29qodj.zipunknown 842680813ac675313376634fbda431c1dd250cbbc7d0c0b622143cd5da12c27en/a 
2022-09-29AqZtfvBnvb.zipunknown e5749db75a81c164708e07c319cedaba6dce9dfa6c4f0c3057f1926ce195b1aan/a 
2022-09-28PoVGbxwLrsODDabkSte.zipunknown 5b6fd6902f97ca434810c1d7dd6a13ed04ea99cf42dc438a581a19d1504eaafbn/a 
2022-09-28gASIlagRTwsGAPMyLg.zipunknown 1ad055408ebad12f13a05cd9c4e2cc4bb700ebd92a2759740b40aa404d917d22n/a