URLhaus Database

You are currently viewing the URLhaus database entry for https://armeriaeantiquariato.it/imm/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634769
URL: https://armeriaeantiquariato.it/imm/?1
URL Status:Offline
Host: armeriaeantiquariato.it
Date added:2023-05-16 21:52:23 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:53:54 UTC to abuse{at}serverplan[dot]com)
Takedown time:2 days, 0 hours, 44 minutes Poor (down since 2023-05-18 22:38:27 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Asvz.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Mhnqjo.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Osjfsayg.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dn/a 
2023-05-18Qcgrzpqz.jsjs 4dfa0373a2fa92b373f578f7f64916f4bcc1d3ca6b72903d536f6c72e9a1e738n/a 
2023-05-18Txzo.jsjs 67ff580532af15d6457fe1b6aa59886c46bd5c72906c86b58aae1e7aab70fa3dVirustotal results 25.42% Quakbot
2023-05-18Qecy.jsjs c3f8749b256087bbe0dcc6d662f467c1d34f701e65acfb75292a72aba0657e26Virustotal results 32.20% 
2023-05-18Juel.jsjs d7c515caf105f46c900f5862443f7dccfef29b7544788a80e4bf47e410fb0106Virustotal results 27.12% 
2023-05-18Jemgeiic.jsjs 649828b67fb96d9addc5f4c9518dfd03c7eaef5dfe3afd081708297f2d160360Virustotal results 25.42% Quakbot
2023-05-18Odjrdn.jsjs f3cf1988e5b288b64fc34cf15045d67a4fcd2c9c61549510e3df907ea1f61cf8Virustotal results 27.12% Quakbot
2023-05-18Lmocau.jsjs 256b5693dd43ba9ac782255a11f52251481f5d72c27042d4b6f9bb05aed317f2Virustotal results 24.14% Quakbot
2023-05-18Uiod.jsjs 7524d906b4d42ae7fd1e5e15cb503e8b54fdc1afa702a0b4e4c5f1d6f99edd1bVirustotal results 30.51% Quakbot
2023-05-18Nxzfpbig.jsjs 7f5092d0b223ae713b6ead45d62c1c63d910a500fc960aeae16e1a1073355c86Virustotal results 25.42% 
2023-05-17Pujwxu.jsjs 0281a8abb9cc25356770caa1340573c19ab7bda7d5303f43a60a52b2b9154067Virustotal results 25.42% Quakbot
2023-05-17Wwtdg.jsjs 8319c01bce9a24d28eeb4e926938d179f37c880ab2aaa26290056ff5089ceae2Virustotal results 27.12% Quakbot
2023-05-17Akoo.jsjs 0836ece78eb77f4b5ebf101fc5e4317ad5554305bff6466db565f247b93b5928n/a Quakbot
2023-05-17Bcbqcy.jsjs c1064ed6356f294c6981938454ee3a3712e5e63930c1554a3c1602eacbd6554dn/a 
2023-05-17Qozxekt.jsjs 12551eef6e57f08df39d1185caa198cce871f9b27d1fb58cd74228fc3a949b99Virustotal results 30.51% Quakbot
2023-05-17Davog.jsjs bf6a2013ee6092e2d291a06d2f69e617b318a1e842a0d559b91fa1b8f8ea1a1dn/a Quakbot
2023-05-17Exop.jsjs ccdaaebf2ae2ce525ab5ccf2b4d74cf6b58e7d9515c21c0d46e2b8e0709eefb6n/a Quakbot
2023-05-17Pnmdabvk.jsjs c54c4059d296ca29bdff5110557d6c49cd9091811c13ff90599cda682364045fn/a Quakbot
2023-05-17Lkvu.jsjs c1187ca24da33a0820a90966e668b01dbf0f1e1abf382bb8297c5cde4efdf452n/a Quakbot
2023-05-17Lixgu.jsjs 03a3de11db4b36c7db9dffc3c56dcf65ae59932f08bb56d238b91aa7a17d5e51n/a Quakbot
2023-05-17Dajqvo.jsjs 933b0eabd82fd70143067b3e8b1150f9634cef0e66bc3b61ee51fa241e927598n/a Quakbot
2023-05-17Yxlxvtbs.jsjs 9684442e25a1393a33cf88b2fbf4eb1d262c553ad3bf1b457ecb6c2e6fbdd9e3n/a Quakbot
2023-05-17Pzuq.jsjs a62edaa9a443f4f8465f25726e3df432b5c58170345dc91be4c53f94256a682cn/a Quakbot
2023-05-17Qzgkw.jsjs 3877a72f63e8bc8c736ad96ff5a672771122f9583dc17f3de69e8485e7f60addn/a Quakbot
2023-05-16Qoeflh.jsjs 20139755ce721bfbe37ac7b4134951e2e332a4810ef2afea4efefd5c966e30cfn/a Quakbot