URLhaus Database

You are currently viewing the URLhaus database entry for https://tourclass.com.br/ii/haqutercia which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2322242
URL: https://tourclass.com.br/ii/haqutercia
URL Status:Offline
Host: tourclass.com.br
Date added:2022-09-28 18:19:34 UTC
Last online:2022-11-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-18 10:52:10 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 month, 24 days, 14 hours, 17 minutes Bad (down since 2022-11-22 08:37:53 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-28qKeMeokZwgMHEab.zipunknown 95158c3cff141cb8a903a0d9558c7897fa2ef74433b8143d7d50c140a0bf7471n/a 
2022-10-22ZkQObylZvCgRFm.zipunknown 4cf1616d169ff1d542bc072d7068e86eb58c538d83351b58100ff262f6d15302n/a 
2022-10-18KwFTfIMf.zipunknown ef98a0420a07132dfe03fae8db16264df1632f043fcb216f906bb3333ef7998en/a 
2022-10-13eRUpBWrcoho.zipunknown a260c4242802ac4adb03b573ebffe0450c8338a4e600eb605592516b5af1645bn/a 
2022-10-07Co2467775172.zipzip 72f957d05218809b1db06f3e641c1cb22b5c43f117e106ed5fe2faba3c28fee0Virustotal results 45.45% Quakbot
2022-09-30P2684069061.zipzip b9a1328f3107582e58d4fef064f2d3998b658ccc513f9e98a513f5606400d9ben/aQuakbot
2022-09-29Gall1273011485.zipzip 2f7a08b42933336200c9cbd06cd7beb0835b47c49e71457dc1b651bf55ff3718n/a 
2022-09-29IXOivEXC.zipunknown a3383e7accdab2ce3c0d30d933f1e490f596058d46a5727eea3fb1e3e9c213cen/a 
2022-09-28YNQeeByhADk.zipunknown 58d25824b55093b18c8be4c040b220c6845a0514c79c1bdaa6f2539ab3878a6fn/a