URLhaus Database

You are currently viewing the URLhaus database entry for https://abuylike.com/ra/dignissimosfugiat.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2617191
URL: https://abuylike.com/ra/dignissimosfugiat.php
URL Status:Offline
Host: abuylike.com
Date added:2023-04-24 19:07:29 UTC
Last online:2023-04-27 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-04-24 19:08:22 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 12 hours, 8 minutes Poor (down since 2023-04-27 07:17:18 UTC)
Tags:bb25 geofenced msi one Qakbot link qbot link Quakbot link TR USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-26Qt.zipzip e4d030f203ac03580df1356470cf8a1a0161f50cc125d4cf8ecbc35f2900fb75Virustotal results 0.00% Quakbot
2023-04-26Orq.zipzip f68a2f89b33b574a89fc43208890a90273aed5e0768ab5665543586aa369a41cVirustotal results 0.00% Quakbot
2023-04-25Wztk.zipzip dcac5f6bd015818e8e469f6dfb76f69ae69c80822b6f3ba5767e10de8ba4a9abVirustotal results 0.00% Quakbot
2023-04-24M.oneunknown 730f5fab3226c290b77c1c6c752accba9f70f2e3c74211952831b675f3e40d54Virustotal results 1.69% 
2023-04-24D.oneunknown 1f390b9dfbe8747d034b134a236cefd673b847d32cb43567595003471c8cdadcVirustotal results 0.00%