URLhaus Database

You are currently viewing the URLhaus database entry for https://tourclass.com.br/ii/tpvuslotatee which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2322198
URL: https://tourclass.com.br/ii/tpvuslotatee
URL Status:Offline
Host: tourclass.com.br
Date added:2022-09-28 18:19:25 UTC
Last online:2022-11-22 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-18 10:52:10 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 month, 24 days, 7 hours, 14 minutes Bad (down since 2022-11-22 01:35:20 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-30cwkTQNtzXqjWx.zipunknown 620b2cddd6f4ed1a36817663dbbf4ffc6363407aea986491b08d564a40c187a6n/a 
2022-10-19fXcAviEgxnET.zipunknown d5948524b7ce8061ff7eed7ad3a9b8edecb611173a35d6bc45e9859b67094f84n/a 
2022-10-11NE1863899108.zipzip 4c17f15332cb10a7bc7edabf480d0495a539e4751f930c0ad20f1d08f0ebd083n/a 
2022-10-09R1797680693.zipzip f25c6ebdc3d773647b348a077f4415a087fb485f0a812dee6ea30753bf8efd51Virustotal results 48.48% Quakbot
2022-09-30G526515451.zipzip 569a4a55543ebf27be0b25407becc195c54461602fe76575ba690070f5780fb8Virustotal results 1.59% 
2022-09-29nclfvGjskYEtX.zipunknown 03cf61bafec6a2fd48d0a8f7a843dd3aba34bf26f86ef0b1aabf05781eb2df05n/a 
2022-09-29G2011800739.zipzip 50b381f133ebaed03c29045bd1baf3eec5c7aac7f36226f453e97f1eb93842f5Virustotal results 1.59% 
2022-09-28gxyNzIXpImclIPYhPqq.zipunknown 5853f74483749f2d257bb51c064250498239d5587f0d04d0ed366b21c2eaf8ccn/a 
2022-09-28dfpGNq.zipunknown f7aa13aa06467485390d3a62fb7ceca6c09f3cfb359d3d9cbf524f6427fdeb13n/a