URLhaus Database

You are currently viewing the URLhaus database entry for https://tourclass.com.br/ii/utmaatto which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2322271
URL: https://tourclass.com.br/ii/utmaatto
URL Status:Offline
Host: tourclass.com.br
Date added:2022-09-28 18:19:40 UTC
Last online:2022-11-26 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-18 10:52:10 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 month, 29 days, 4 hours, 42 minutes Bad (down since 2022-11-26 23:03:02 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-30xlzAvusoLQKulrrkl.zipunknown 383e4826b911eb9017182363983c4497ac56710319b2b3ea8cc5619b18a3305dn/a 
2022-10-23gQMvOBgDnzRA.zipunknown cbc0a7e835d34a48b1211f5f59ad2964a348f96e79eed44d3f89cd382997b103n/a 
2022-10-19auSFLTRLGup.zipunknown 0dfcaa1813301cde306d234e1c590be8500b8ff8189e899dfecf8e09e5f9224an/a 
2022-10-11Gall2872772551.zipzip 28b260d0e636fb5581ce6183f8c082a6b06d20604db7ce30836ba6969bfe0d18n/a 
2022-10-09R3173967428.zipzip 62706b5a3fa9c9ba49e15d064c07692139dcf69bef8dd8168667c73c2edc8d23Virustotal results 45.45% Quakbot
2022-09-30CA2249657726.zipzip b3bc322bcfece426ea68d9a3c0afd35df1c33ad54fdd6c781c70c74aa25659c4n/a 
2022-09-30G3806042878.zipzip e13acedfaf5991129224a05c15da152257843b508c342aeeb671bc3fd2f6e653Virustotal results 1.59% 
2022-09-29G4177390907.zipzip 82466138c07d29af2e81efce6a230f9a747fd6c48bcc0c121f905a9a2f5930ecVirustotal results 4.76% 
2022-09-29TsXMjtJAoXBxtEfRhT.zipunknown fb97871b40ea5bf55dde996fe164f8d1e58d1e4b3dfbcca73e3268a1d64592a2n/a 
2022-09-28vSQsLhaxyO.zipunknown c8f2fc00a5540c679a9ebb5023f40897a6bed77c0d56631b65bb4b8cb2f28a01n/a