URLhaus Database

You are currently viewing the URLhaus database entry for https://itjobsavenue.com/qeva/dxaebpnesitio which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2346803
URL: https://itjobsavenue.com/qeva/dxaebpnesitio
URL Status:Offline
Host: itjobsavenue.com
Date added:2022-10-03 15:15:16 UTC
Last online:2022-10-28 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-22 00:09:10 UTC to abuse{at}hostinger[dot]com)
Takedown time:24 days, 1 hours, 30 minutes Bad (down since 2022-10-28 04:53:20 UTC)
Tags:bb Qakbot link qbot link Quakbot link R871 TR zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-16GVCwPqQtaYHcFoxAuH.zipunknown 48cf9cb12b37e58dbc1d867e73b75302b103ad7268596208e60565955df0dcfdn/a 
2022-10-11R2880792911.zipzip 77789b6c012a313b7c14ca2c78a10dddd24c16c33b3d44907e9e5f7432704f37Virustotal results 1.56% 
2022-10-08Co2835497681.zipzip 9f679b23a88b89ad762b72ac1439cc4a6b43a11566a44d20750f99be7d132cd8Virustotal results 45.45% Quakbot
2022-10-06utMnasoimial501572077.zipzip c5f34a512c3f493b529c80d21240543e947993c655718a66ef53f44c2cb7e91fVirustotal results 23.44% Quakbot
2022-10-04ArtItem2836482243.zipzip fc600017ebd6e3866e6ac4b407962a5f1f9befe4a4b1966874d523fd4a984d31Virustotal results 4.08%Quakbot