URLhaus Database

You are currently viewing the URLhaus database entry for https://sudaksha.com/ed/etautem.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2623515
URL: https://sudaksha.com/ed/etautem.php
URL Status:Offline
Host: sudaksha.com
Date added:2023-05-03 16:28:33 UTC
Last online:2023-05-06 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100109709 created on 2023-05-03 16:30:22 UTC)
Takedown time:2 days, 12 hours, 58 minutes Poor (down since 2023-05-06 05:29:12 UTC)
Tags:BB26 geofenced js Qakbot link qbot link Quakbot link TR USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-05Vxlmkp.zipzip 2854e32d82affd16937c49ed5abb7f546a4cb7cbb81febc86d669fff5f416a75Virustotal results 5.00% Quakbot
2023-05-05Nwf.zipzip a66d9d29518c7f348899b7c6bf3f50d6d3ea768b07283651b68408fc772a1f81Virustotal results 0.00% Quakbot
2023-05-04Wczb.zipzip e7105ca829488c50813c29032309299ca271e5b64853d15bb71a7f4dd388db42Virustotal results 0.00% Quakbot
2023-05-04Ubi.zipzip 847b4aaadc5aec14c64d5ed285a685344c574d4361fc40c0f659670a6386e7a2Virustotal results 3.28% Quakbot
2023-05-03Kg.zipzip abb3f2e40fe390ffc800f0733b834ebe6cf0043cba22669f6332eae464b8662cn/a 
2023-05-03Cufa.zipzip db65a3e91cb3706016b9cf5be2ff2fac4ab08e08dd1db554a4568a878b63f3fbn/a