URLhaus Database

You are currently viewing the URLhaus database entry for https://alreemrealestate.com/it/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633987
URL: https://alreemrealestate.com/it/?1
URL Status:Offline
Host: alreemrealestate.com
Date added:2023-05-16 13:14:47 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:17:38 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 9 hours, 29 minutes Poor (down since 2023-05-18 22:46:46 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ozaptcm.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Hwva.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Zujvr.jsjs c4548bd27e2bbb12e304162c0eba3a3224f3318bf59abde62ff97a60f8554857n/a 
2023-05-18Yjouaosq.jsjs 6637cd86cb6d1780d474d49c347f8accc08a24f73ec7d212ecaa591e370d7e1dn/a 
2023-05-18Elubnhd.jsjs 90fa0f56e8df4147606c0590d9bf8794253f48339dcf3295c0bd6d7b2dd0664an/a Quakbot
2023-05-18Oovhy.jsjs 1bb623b986a2a31d7b68f61ab99a793274bcd030e6ff4daedab6e150252b27b1Virustotal results 25.42% Quakbot
2023-05-18Yisvseo.jsjs 38158794f34f920ddf3cc1bd5048a2d8be22b550ea27c09a0c746d59e22b3fc6Virustotal results 32.20% Quakbot
2023-05-18Byicbi.jsjs 561eeabd5f230ff8d733b3aa53f761558b65f54ba6d32241bf0350b4e136b808n/a 
2023-05-18Rujqn.jsjs 4422126c61949a9848ddc759de968eb699c5364973a271dc9aac631121591d13Virustotal results 27.12% Quakbot
2023-05-18Gdrfde.jsjs 0eb9fa07ffbdae465ca7afa7b68b6b38311315046844cd6ac97c9e3b77d5fe99n/a Quakbot
2023-05-18Hfiwg.jsjs 24579cbeb7c33196bff853d67ce422776e45c942b057519eb6a6c453ed30ac62Virustotal results 30.51% 
2023-05-18Dcvcleny.jsjs 8290e44e2bd6431a3cb8fce93c83b97d4710c63bffe7f1eb93db3282ae17b5f6Virustotal results 27.12% Quakbot
2023-05-17Kbxa.jsjs 14ce409dfb31225a9aa73965aca14ef09852a03cf69033bf2deac2a816796a31n/a 
2023-05-17Ymhx.jsjs c977474e11ea0066144f719c48b4f2d5ae32da3a13eab7d64cb3433546b8d738n/a Quakbot
2023-05-17Ejqszz.jsjs c66769c1beccde8a71bc20172ba3978dfa20fa8e27c21976b94c10327af6d4caVirustotal results 27.12% Quakbot
2023-05-17Lypbp.jsjs 3f3578034596c52f8ed357e2c3f37660c2f5af439da7fde722d26c629f457d03n/a Quakbot
2023-05-17Oqbx.jsjs b80551abdf45ba18befb113fb4c02517cb49680bde72f8ae92ef07e61857ec89n/a 
2023-05-17Kxshod.jsjs 35c35c65a46137ab025bfda60be1ea1c10a10b9cae6e337415b9c7b2ebd3df3en/a Quakbot
2023-05-17Siic.jsjs 447b96999dd079d4e5bbdefc464fbae41be6c1d6f55fa0d6dc0cf9db6f3490b2n/a Quakbot
2023-05-17Xqmrzfq.jsjs d539b753543af560dce23ae456fac8033ea352f2d003120b34332e8aef45cde4n/a Quakbot
2023-05-17Detiog.jsjs da4abec6783ef301a11f17e4614ffdc312e907f98322195f9f9c4fddea92ef30n/a Quakbot
2023-05-17Aauysbvv.jsjs eb2c1d40111d79918bfbaf21100c2b305dd694d9e0fe7e9dd3668bfed6aadc3an/a Quakbot
2023-05-17Lwpnrx.jsjs 772acd809f8e18e0060a9d61e8ff49a1be442f54f79eba1249058da9d074d321n/a Quakbot
2023-05-17Rcenutb.jsjs b21934903a478ffaae5d914f5d8864d82005ca34908dfe31243270188234f695n/a 
2023-05-17Mgly.jsjs 8284464c1649ec1192e326dec9e030366eef68d519649f1630c1fb629edb030bn/a Quakbot
2023-05-16Rlwharf.jsjs 3216f60fe1372004045b846e9342451ba59e06a66eb234d07303b25ecf0c9085n/a Quakbot
2023-05-16Ltibjke.jsjs d0222655c9ffa372f29f64d5a668e784feee4859d440f0e0e2d855d7cee4df93n/a Quakbot
2023-05-16Sakoyrpb.jsjs 045dae70d3754c1c18780f0ad6f770a8600fb0cae847a050326dbd8c1be53b33n/a Quakbot
2023-05-16Tzdjazy.jsjs 666bb0db52bc502d8f952805c300404d95f5ea2429a3938426a904db7d6b1a32n/a Quakbot
2023-05-16Srgta.jsjs 7902f80cbe80b4ef3442fad6e5c8af1f2652432a562deb0ab529c081bd4fc597n/a 
2023-05-16Prdrylz.jsjs ec9ecb29de95e34a0dbbcc0d2fc151359835ad923a5bc1d5817b8565fc9c3ba6n/a 
2023-05-16Blaysxvo.jsjs 57c4221e43b7de59374e0f2812e1b5a9ee14f773cdd051b449a0eb5af32f25e5n/a 
2023-05-16Oqwn.jsjs 32fc410a54f73dc2fe8d4eb077c9dce33bdc747ac6318c058a099b34816c632bn/a Quakbot