URLhaus Database

You are currently viewing the URLhaus database entry for https://raengenharias.com.br/ee/ltentusaecuds which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2340091
URL: https://raengenharias.com.br/ee/ltentusaecuds
URL Status:Offline
Host: raengenharias.com.br
Date added:2022-09-30 21:56:04 UTC
Last online:2022-11-29 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-02 09:20:14 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:1 month, 28 days, 12 hours, 4 minutes Bad (down since 2022-11-29 21:24:54 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-24sIBnOForzPMKsNjIUXU.zipunknown a17a29597f9f08c5571e0557d17312cf25412c264c7ccb0a10dcf3e3ff51015fn/a 
2022-11-04wPOw.zipunknown 55e7acdf532eff6fa89b777542de66a38392cc4bcd18b4081be0486ba658c5d9n/a 
2022-10-25hBZXgnGWwlTipoM.zipunknown 0ef1301d587731a08f2bfc832a17249451a268ea372c9523053f36ca6fad25cen/a 
2022-10-20SLDOrKVeySSaZ.zipunknown 2556a55ab349861f80650ce5361fe43ad4659d63c14b86593222131ba1574639n/a 
2022-10-13MyELinafTha.zipunknown 5e58b1fa4bfc4f7e0e78079b8feddd44a5c899a13dd51348a5131367543d305bn/a 
2022-10-09R2243259735.zipzip db7658fc2bbb210a43a98863dfe6de624f3199ad44f9c84d4de7b87bcabc0b8cVirustotal results 48.48% Quakbot
2022-10-06Co2351446596.zipzip 2fd7788edea1ed3f1ce684e5ddcd67ec24b5f74ea9dfd465b7dfcc775e8acd93Virustotal results 22.73% Quakbot
2022-10-02Card323766404.zipzip 1f153579e8d1ce6ed85b51000e6383b137ebb2d67b998c3293592526872baf4cVirustotal results 0.00%