URLhaus Database

You are currently viewing the URLhaus database entry for https://meditourz.com/ousl/atpovlesuds which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2337375
URL: https://meditourz.com/ousl/atpovlesuds
URL Status:Offline
Host: meditourz.com
Date added:2022-09-30 21:30:24 UTC
Last online:2022-11-02 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-03 14:03:10 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 month, 0 days, 7 hours, 29 minutes Bad (down since 2022-11-02 21:32:41 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-25YzbIXyciuBIxyfIC.zipunknown 0648b3216158618e3077452dc52c520524aa0f05acdd8be240439706d431611dn/a 
2022-10-23ZZPPQxEOCaKbbIow.zipunknown d5e2469c34de66ff81346797f0726c81f0cd8f6d87227744b937c47852836dd7n/a 
2022-10-15MiTOeGosXEV.zipunknown cf356219e3c440358611cd2b4832b1e032e273fb4ae9386f9048448560e29b9cn/a 
2022-10-13xfDMgzf.zipunknown 1c6c8d17f4583a39cd05ab08dd595ae7232a6cd3cb068f159229735c679b4861n/a 
2022-10-03CA2854078868.zipzip 111194e0b14ace3d3f4524ce008b69a34cf527d95b0b6341f91121ea0ca12233Virustotal results 16.13%