URLhaus Database

You are currently viewing the URLhaus database entry for https://raengenharias.com.br/ee/qeridumurem which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2339999
URL: https://raengenharias.com.br/ee/qeridumurem
URL Status:Offline
Host: raengenharias.com.br
Date added:2022-09-30 21:55:42 UTC
Last online:2022-11-29 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-02 20:51:12 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:1 month, 28 days, 0 hours, 3 minutes Bad (down since 2022-11-29 20:54:36 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-21QFhnzSB.zipunknown b4667f11b828770999cecc0eb6023b9cfcf3cf73ed6f1f135bcc3ddd0bbf7265n/a 
2022-10-29IooLKSiowtJYEIG.zipunknown 5e821ac98d348e2bdd0433ac9a6d94e9e139dd025d8ec5b8d1b5064c294cd485n/a 
2022-10-24HfrLhMbKJjB.zipunknown 3d324c6da4e02a43f9ff749aa997ccec8d60078260098ae26960c83a796d63d0n/a 
2022-10-15JZavRfWgfmWCUFb.zipunknown 4ff4d5171b15ec25843fefbeeed08f5fdc01d63593c985b16df2a4f8072596dcn/a 
2022-10-14qoZKhMYzL.zipunknown 9e3562a4fe00862fb3267916fd93f22493ceb2ed29cd69be4c48c7e6f4b337c6n/a 
2022-10-09R3654999308.zipzip fb05b8a0334b697465c26ad4ed88d07ff0800e5555fd61c71829ac2a27a77ab5Virustotal results 47.69% Quakbot
2022-10-06R4060060636.zipzip 1dcc126d2aacb87f24153cf24411a4a39e299c8734faee69e80743d06139efbdVirustotal results 19.70% Quakbot
2022-10-02CA1066776375.zipzip 54120b5024f9173bc431fa385ee9c6210d3212a9d25b75a1e84736eabfbbfd4cVirustotal results 3.23%