URLhaus Database

You are currently viewing the URLhaus database entry for https://mentorialegado.com.br/mnm/itlsopauuqvs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2320350
URL: https://mentorialegado.com.br/mnm/itlsopauuqvs
URL Status:Offline
Host: mentorialegado.com.br
Date added:2022-09-28 18:05:16 UTC
Last online:2022-11-30 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 18:06:23 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 months, 2 days, 12 hours, 12 minutes Bad (down since 2022-11-30 06:19:07 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-24vrXILWwmCgxtovagnzc.zipunknown 7be97635d1d9a3c60222cb92f267dec547a93a4aa8d881ce8e5fe8c2c03e58dfn/a 
2022-10-29XEWd.zipunknown a2adde157e450868971492519222a28d43329eac45550d1505bb31ed9d551d0en/a 
2022-10-20ouRDn.zipunknown 3baff9e03be699097e641ae3c6c44356e44fc8faa2209a6a699f36176f14566an/a 
2022-10-12Gall1611129807.zipzip 0effa93a7364ea18e10b82cf04b5581a53f802881e60c04dda235b09a259d7ccVirustotal results 3.12% 
2022-09-30G1955283858.zipzip 43f68b61f1ff960184797687913d21a70a67432314c4d859b75611015c32f971Virustotal results 15.87% 
2022-09-29aAQGxnDwRdYSkLfcEK.zipunknown b53a028c6c0c27632a84453aba382a4b29cdab3c0009bf4bd201b985fa507956n/a 
2022-09-29RrVWVdZwXVwqQ.zipunknown d2fec539df919bf14317705c151b13221771962c08b48c04eb6e2852168fcaecn/a 
2022-09-28xNJbpKNJxN.zipunknown b7e1049868c512875e3ea6163c2ba17fe8aca051af865994cfab2295a0e504f3n/a