URLhaus Database

You are currently viewing the URLhaus database entry for https://meditourz.com/ousl/uqmnacuasqeurto which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2337341
URL: https://meditourz.com/ousl/uqmnacuasqeurto
URL Status:Offline
Host: meditourz.com
Date added:2022-09-30 21:30:16 UTC
Last online:2022-11-05 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-30 21:31:15 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 month, 5 days, 13 hours, 29 minutes Bad (down since 2022-11-05 11:00:43 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-29ScjmO.zipunknown 9e8ae3b3a1d00c802cb39f4a3244f65703f384329be25da7b5369f6a615c2fe8n/a 
2022-10-22DNdVcJACfuABVv.zipunknown 367f6ef121f06b513f79c02dc88c7afa2a91075d45c3e458d6221a7c38419b73n/a 
2022-10-19mvOro.zipunknown 37765fcdfd621e10b68858122203130ea5c16d2eb86f2f009a1c4abde0b28622n/a 
2022-10-12Of3508339730.zipzip f75512722ddeb0a0d18f3bb3c67daf4acb9632ceda6ee82bd6d2165a574b4c8fVirustotal results 3.12% 
2022-10-04R3528041144.zipzip 03a6b8714dc6089e6673593953b8925a219a710c0c94a8303898e65b11c50543n/a 
2022-10-02C313838311.zipzip ef986141f81d9304f9ebd0fdaec86be09e85eedc843967fd9633b0c0c40156a5Virustotal results 11.29% 
2022-09-30Card564325483.zipzip e2d6cdf0fa017413f3f23335ec58ec44c2a459acb30a55a2f274dbebf1193f8dn/a