URLhaus Database

You are currently viewing the URLhaus database entry for https://erengenharia.net.br/tpi/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634841
URL: https://erengenharia.net.br/tpi/?1
URL Status:Offline
Host: erengenharia.net.br
Date added:2023-05-16 21:54:14 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:15 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 0 hours, 12 minutes Poor (down since 2023-05-18 22:07:30 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Rueo.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Ohqkjbho.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Cfou.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Dsiubcu.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Hlpmj.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dn/a 
2023-05-18Ooiepozz.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-18Tqjx.jsjs 8deae0dc00f63d06da4b8491f06c909682b192af1c7ae4467703241c34a509ebn/a Quakbot
2023-05-18Pybdwkh.jsjs 568dbf92f0bf53b20857f863e58e7f82287fe96c9dc066c782f5f82c64287a75Virustotal results 25.00% GuLoader
2023-05-18Zkjjlxs.jsjs 119865e21bd0f564ac17f9e36940d9360139b87392fa02dce3483f1a789ab4abVirustotal results 24.14% Quakbot
2023-05-18Lwxzu.jsjs 9f83e5346339db98db754ee60a6d9de3db2ecaf650f4590c2a11ad9e484c46a2n/a Quakbot
2023-05-18Pgejcg.jsjs 8a9af030d5759e428811a44e1582012c64fdef7059286c4c1693f13566e2d3b1n/a Quakbot
2023-05-18Otyijn.jsjs 1cd77905385f0c42fc817556a8df0df76650c7bcc4f1d670bfdf4cefe71c5d76n/a Quakbot
2023-05-18Ghomurxx.jsjs 783e0a457afb1237e0956e6ff847bfcdb49ee23036f51b4621b534f54d67112cn/a Quakbot
2023-05-18Nlreqrs.jsjs 9d9924b0f0e33e1b74db34d25035395c2f29b1c29926ab16bfec2e29f30c8b81Virustotal results 27.12% Quakbot
2023-05-17Ycneag.jsjs 649828b67fb96d9addc5f4c9518dfd03c7eaef5dfe3afd081708297f2d160360Virustotal results 25.42% Quakbot
2023-05-17Xzcadxnl.jsjs 784d0c23a7299fe8f5a79ce4f83765cd48535cf1afc25d542a0f854f8049d149Virustotal results 27.12% 
2023-05-17Brvld.jsjs efc10c85b0f60f774980c7250e0358ab61ded2a4d2f8fed854bf14d05af6908eVirustotal results 6.90% Quakbot
2023-05-17Kymcxa.jsjs 860e36fc5c8d21dbe486debbb3dc78ef1409446eb46d7c84b937f01cd3075364Virustotal results 29.31% 
2023-05-17Tvizpejg.jsjs e2cd2a44ac9c613f289c14a9d30244223f9949818db49dc69c73a5efc442a948n/a Quakbot
2023-05-17Uppsrgm.jsjs 4779dbaf4f01d866b1dd6a2cdeb855c53a82951952ba41e9af73be849bc9116bn/a Quakbot
2023-05-17Oszrer.jsjs f4fb9e206467712813d87a31c0ea3285bf1a5ad9658839ca77ac0a61dcbf0693n/a Quakbot
2023-05-17Mozngae.jsjs 7d4c05f2b21fe02c34ffc3bc7077929482fa7cdbc01c894e2647cf6e38ab20bbn/a Quakbot
2023-05-17Tdzjyuhz.jsjs 16c3976c2288cf00a4735c2bea4431584d361fd5fcbc8fb262d27cc4c44203d7n/a Quakbot
2023-05-17Zgyw.jsjs 417745552499fc229b2d75a9743d7210f76a7246c3fd60660ecbfc2bbbe3f18an/a Quakbot
2023-05-17Dslec.jsjs 5c7258c8cc321d7c8c1907ed9e7c32c84db8f274f2bba1b2db63e1b99f5df7fbn/a Quakbot
2023-05-17Lwrao.jsjs 221d9a5e01ea034a954f8cbdd7dc80243ed4ab378538fbcc7cedb5795ae6711dn/a 
2023-05-17Catazebx.jsjs 4ef087162ffc543dc1ec46e7068fe04472a4874b86c4ae74f6b7cdaad81458c4n/a Quakbot
2023-05-16Pkzv.jsjs 950e1bc432fe2c2a2333fbdfc73e284b851663b75fd6148809aa53629dbe63b0n/a Quakbot
2023-05-16Kblkqgm.jsjs d63714cf0ac451222dbec8c8e7a3636ccf81ef555fca0bb3bd674eeec4db01e4n/a Quakbot