URLhaus Database

You are currently viewing the URLhaus database entry for https://prauditores.com/ut/lietstve which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2339850
URL: https://prauditores.com/ut/lietstve
URL Status:Offline
Host: prauditores.com
Date added:2022-09-30 21:54:23 UTC
Last online:2022-12-02 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-01 16:45:12 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 months, 1 days, 17 hours, 58 minutes Bad (down since 2022-12-02 10:44:01 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-27TLIjioXR.zipunknown 374194ffd5fb04aaf1157d254c0049dbedcf6f987bc9c1ab1fad0dfba80a96f3n/a 
2022-11-20EyHdBEHeejRhIBevBIy.zipunknown 2c3682b1382bbb95e8269b67f5aa7031b9d6dfb7a2d576e3b6313da6bd65f6bfn/a 
2022-11-15ZlEcYBJbKe.zipunknown 2b3632dcd5f663d3e0f7db91045615070149bd609b01092d4d0e9619e676ed5dn/a 
2022-10-24VSnGkf.zipunknown 8496f8591a5fcc6c56602284fd1555f471511a8dcc21d7fd5ac6d4755f339954n/a 
2022-10-16sugtvKMLZaXhy.zipunknown fb8a3b29580507a1938c99e421206fe65d5a6c7c036ac87e8a63ab078a973bf8n/a 
2022-10-10Co2194527022.zipzip 4bc67d62d89e1f2e81cab3a738660932e8aa94c4a7852ad8333bf93dd4e0cf36Virustotal results 43.94% Quakbot
2022-10-04MHjjDDGKKjzdqrgvTob.zipunknown 6b7bbe96bfb4e5a552115e542fc50bd854126a8031a2a3e942aea48a6a306c9dn/a 
2022-10-01Card2873415187.zipzip 707a9191aa538236cea09f360b1b999856eba9e4642a8e69cef475708fa4a999n/a