URLhaus Database

You are currently viewing the URLhaus database entry for https://meditourz.com/ousl/oquinsn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2337339
URL: https://meditourz.com/ousl/oquinsn
URL Status:Offline
Host: meditourz.com
Date added:2022-09-30 21:30:16 UTC
Last online:2022-11-04 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-02 11:49:14 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 month, 3 days, 2 hours, 47 minutes Bad (down since 2022-11-04 14:36:36 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-25ZgfBB.zipunknown d177d7bf73313bdde7d6ea57b1d755024e6b323edb1323f757bfa406e93b61cdn/a 
2022-10-19DOzOuIjwPEWGEVlV.zipunknown d4c63d193d63abe4b1a07925eb75f286ac0111ec1707159499f95d6b97813d55n/a 
2022-10-14lyavIXIWOTke.zipunknown bd9ef6a546e4d277a52665c469782c5c89408fd613fe3df9dbb6a54b55314a81n/a 
2022-10-05EKctjQUJDZhlOmrxgCI.zipunknown e2561ad4ffa147ee8d4a110ba151399dd67473e5434186972d9b9276bbe259adn/a 
2022-10-02Card3528532819.zipzip e53d66a9cc7500c8ca6dbd8382366e33954f93bd357aa5309e89f3c65e0e78a5Virustotal results 1.59%