URLhaus Database

You are currently viewing the URLhaus database entry for https://datastatresearch.org/eutu/vitaeex.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2623291
URL: https://datastatresearch.org/eutu/vitaeex.php
URL Status:Offline
Host: datastatresearch.org
Date added:2023-05-03 16:26:33 UTC
Last online:2023-05-05 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-03 16:28:44 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 12 hours, 20 minutes Poor (down since 2023-05-05 04:48:46 UTC)
Tags:BB26 geofenced js Qakbot link qbot link Quakbot link TR USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-04Dwru.zipzip 788486c0de58683c99677250b9beaf865e81d0af5236a937ce84b700d39a6edcVirustotal results 3.28% Quakbot
2023-05-04Dd.zipzip aebe88f8057dff8f66e3fbf5caf32f138fbe4a6b9a8d796fe0875de69ff26357Virustotal results 4.92% 
2023-05-03Xgvq.zipzip d927f2608ddcb60354543933b10c4b2e1f4988628432e36180078ec45064e348n/a 
2023-05-03Nhuh.zipzip 7338ab36fa75f8a827ce8890db952ae3dd0d1e6e559c82ad9ad9a08aa7333f0en/a Quakbot