URLhaus Database

You are currently viewing the URLhaus database entry for https://forzzagym.com.mx/tuag/araiqiuuaprt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2318879
URL: https://forzzagym.com.mx/tuag/araiqiuuaprt
URL Status:Offline
Host: forzzagym.com.mx
Date added:2022-09-28 17:54:25 UTC
Last online:2022-10-28 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 17:55:07 UTC to abuse{at}hostgator[dot]com)
Takedown time:29 days, 13 hours, 58 minutes Bad (down since 2022-10-28 07:53:33 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-20mgmBiTPXsEzfMstM.zipunknown 0213b86634a6234c16c280ef42728064ec0a9660141fd6803aaa5379cd4d2f18n/a 
2022-10-03C709841144.zipzip 75fcd90ec667249c34ae21c9de52c20d6625529e0c52e3c15f3dc990701a82a8n/a 
2022-10-01Card716704856.zipzip c4295a1224da2e9d5c89a19dd479a28609cc0b5d79a8b649f14b4f3baf9425a4n/a 
2022-09-30Gall2918396884.zipzip 8d2e8f87cd4151d8c71db20c4f761f7528db742e3fdd6256e039b2e486fd937dn/a 
2022-09-30VukRAZEklG.zipunknown 1e6236fdf17a1c35d4872a5b62af8689c47f2c274b57a7ab3070b1083d34f246n/a 
2022-09-29eFNGydGnkEF.zipunknown 7f3b60aaca55bb8bea1b24ccaf0775bd0a7ef63d195521edcffe40412cbf941fn/a 
2022-09-29ZzkANi.zipunknown 05d2fad4ada8f6211749f30a61d1c268c0d34521c7ea7b7dd405e1a9f89defa4n/a 
2022-09-28DYyYDlsJlYMwFlkT.zipunknown 92d614cf8532868835c833c289a99f43e026b862ef71b6f9ca44895e9d1266fen/a