URLhaus Database

You are currently viewing the URLhaus database entry for https://raengenharias.com.br/ee/tealilomti which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2339938
URL: https://raengenharias.com.br/ee/tealilomti
URL Status:Offline
Host: raengenharias.com.br
Date added:2022-09-30 21:55:25 UTC
Last online:2022-12-02 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-05 18:33:12 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:1 month, 27 days, 21 hours, 29 minutes Bad (down since 2022-12-02 16:03:09 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-27TySDlwy.zipunknown 4537e478e4ee80f5b69499f87b492bd389e5bd70b577d55282156ae5eb12d19fn/a 
2022-11-21qAbTcDyTKr.zipunknown 77f88fb5a9957cd3356c1742384d8f1ebfd7c6ef41796b74d5d2a602f33dce48n/a 
2022-11-17LbvIhyUbnhZgCEC.zipunknown d017b57ca49b771939a6dc0a1ca0a4f8744550775eaab19a8f5c6df68d59efa5n/a 
2022-11-01kucWikPHo.zipunknown 414be2da261958224cd42c7b1593159c3dbed3bf418ddb16a478a2fd5a9f29f6n/a 
2022-10-29RwRcuCswaIRAk.zipunknown 4697e99d2978b5896ee5a3f6dabf6a8eff40ed057b1ddffa1c69028500f0e43en/a 
2022-10-19waSdiinHOZUhRdO.zipunknown 075ff79619561e4bd2acdc437923d55ef7c565a8a3b5ac2c048a997131e52cd3n/a 
2022-10-12SWlKVKaQsLoKtdtAUO.zipunknown 106a8347e0a97519b13a383712f2f56e927620722417c097065189c43d7e5440n/a 
2022-10-10R1833645019.zipzip 17fb21a87d7962938cb0a4614ae82872e2216c9d31a4f01fe5c34f4c0dde4d75Virustotal results 43.94% Quakbot
2022-10-08Co2859335289.zipzip 5f0631904383b18444ad76862b703a0bf672b99d90b8a402bd1857fcea51e824Virustotal results 45.45% Quakbot
2022-10-06Co1830488851.zipzip 6431f9ae63dd51fb8c36093f8cd5d9f5a57df4668719afbce71ae82c2ecc92a2Virustotal results 21.21% Quakbot
2022-10-05CA1832644538.zipzip f64febeaecfa110482a806903acf70dc4f406785fc15da31d4e4db425926a18fn/a Quakbot