URLhaus Database

You are currently viewing the URLhaus database entry for https://meditourz.com/ousl/etadienqieleu which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2337427
URL: https://meditourz.com/ousl/etadienqieleu
URL Status:Offline
Host: meditourz.com
Date added:2022-09-30 21:30:35 UTC
Last online:2022-11-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-02 08:27:10 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 month, 2 days, 9 hours, 33 minutes Bad (down since 2022-11-03 18:00:48 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-27JQWWFiZa.zipunknown 30d43e5042687b433e30513ce051a0f822000a1e670a3b7d1e008b1d17895a5fn/a 
2022-10-16qLkLdOFmG.zipunknown 38f3c4b7fc8ca70f2059423170efd7d9cee07c14c113f70704118b33988de24an/a 
2022-10-12gWgjp.zipunknown dcfa9074dacbccab207759bb6f8b1dc583a68fc3accaf66f6eb5ae9c232174b6n/a 
2022-10-02Gall4259063229.zipzip 85c997fb312e1e09abecb37de9af41c7ee7b9264bf6001720f80250bd050508cVirustotal results 3.33%