URLhaus Database

You are currently viewing the URLhaus database entry for https://raengenharias.com.br/ee/oalultieq which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2339996
URL: https://raengenharias.com.br/ee/oalultieq
URL Status:Offline
Host: raengenharias.com.br
Date added:2022-09-30 21:55:41 UTC
Last online:2022-12-02 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-02 01:40:18 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:2 months, 1 days, 17 hours, 4 minutes Bad (down since 2022-12-02 18:44:38 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-27mTuV.zipunknown f1a8241d4470409efcfd12cbf26f4dadfff620a607191e2073d1f975c947905bn/a 
2022-11-24faGwTUAQRGguIq.zipunknown a5c7de72162620b47b2b427f087808c514a9de14b1e726150e11006425c829fen/a 
2022-11-17NvrTplcrSNYzPEZOy.zipunknown de39373cc9e0098fbc216f2629dcae849650c570af1b86115c6e8206e1a03484n/a 
2022-10-31kGNXyCJLM.zipunknown bd67e5100efc60744f574cffce1d68e5108eadaa131b62800aa87f5a065c2a93n/a 
2022-10-26fzrrTESAvyTGsUyMem.zipunknown 6114a127fa92a8fb27ee1509163de9b75d12bda13719bdfe2860589297c3324en/a 
2022-10-20OvjW.zipunknown 0ce55ffccb4fc626193f343092bb3a325b45f030b4ad11ecef4103326be7925dn/a 
2022-10-13rbuPs.zipunknown 207f5baf6643b85d960257107b3959827a7fc1a547566bf9aa7fe74c7d818776n/a 
2022-10-09Co3364630110.zipzip c69e335630f6d822755fb9d0fedadbd48f4c5eb50156fd0603009426d255e198Virustotal results 46.97% Quakbot
2022-10-04Co3430486345.zipzip f22835c5f73c12058fe09182a82a288c9dbf5dbade13a48dd2f78d3f8cc9de7fVirustotal results 3.23% 
2022-10-02C1859055517.zipzip ece0234f376f90489b0ff06bea60a1e78c5a93cf7c0c4b4dc6dd5686f79645abVirustotal results 3.23%