URLhaus Database

You are currently viewing the URLhaus database entry for https://thirumularresearch.com/vfa/stutaiecnn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2322061
URL: https://thirumularresearch.com/vfa/stutaiecnn
URL Status:Offline
Host: thirumularresearch.com
Date added:2022-09-28 18:17:44 UTC
Last online:2022-10-10 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-29 04:44:15 UTC to abuse{at}hostgator[dot]com)
Takedown time:11 days, 1 hours, 19 minutes Bad (down since 2022-10-10 06:03:50 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-05Gall2205378605.zipzip 39014cd29515b6ae15ca14f9d3997e3740a47b141a74f7257c32c35cdb47a615n/a Quakbot
2022-10-01Card3218084714.zipzip 306991dc59ef145f1015048d0a0ef1f90800fa87a1a1563d0ca8aba37a7e88fan/a 
2022-09-30G2737061855.zipzip ebe99fac07d78a336e967a2bb10882fdabdae6101dc74c0526a0a5616796da51Virustotal results 1.59% 
2022-09-29G209534787.zipzip c94ad4ae7e56101b3e32cb105afd6910e4fb50b3f39e4da8cc928f2e7cdea01an/a 
2022-09-29Eteum1883523910.zipzip 6e79cb4d61e1ad805098f8674057c03905b136c681ef4c670b828f0b5e2fca46n/a