URLhaus Database

You are currently viewing the URLhaus database entry for https://raengenharias.com.br/ee/slaortudoeolm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2340252
URL: https://raengenharias.com.br/ee/slaortudoeolm
URL Status:Offline
Host: raengenharias.com.br
Date added:2022-09-30 21:56:49 UTC
Last online:2022-11-29 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-01 05:34:13 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:1 month, 29 days, 16 hours, 42 minutes Bad (down since 2022-11-29 22:16:50 UTC)
Tags:bb Qakbot link qbot link Quakbot link TR U492 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-19kFELTivxoMhmywDW.zipunknown ddb3fff86b1e26f6e75297798b2cca613b6bc2b83733fb181bc98bc196fe17e6n/a 
2022-10-27YtbZVClqU.zipunknown bd1d67d4236f58a975030e079d702565b34f0596af592ddfcac6f195f3ec9f26n/a 
2022-10-15PYrokbKtVtyeztf.zipunknown f616423fc6e6e183243f3fab2c72d707a777716770cc7aea0e2410de7331ecd6n/a 
2022-10-11O-2365109483.zipzip 9732b94d69e03e3974afb425d249c6eab797746298f720e4dd93c2eedbf3f2c4n/a 
2022-10-07R2965634726.zipzip e740b6fe39f9f3faba6b224e98c1d72828e532ed7f5152ce06941b78edced65aVirustotal results 49.23% Quakbot
2022-10-04Co568149495.zipzip 614b26921bfbce9d2579b7d6a4e35ee1b09cd69f96994755ebeea3e4e5fff0a2n/a 
2022-10-01erreeqorNu3422002511.zipzip 516634cb3040068c5569a2cdaaad573653048dfcbbb36d758689633b593f5953n/a