URLhaus Database

You are currently viewing the URLhaus database entry for https://formuladeseducao.com/ee/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634868
URL: https://formuladeseducao.com/ee/?1
URL Status:Offline
Host: formuladeseducao.com
Date added:2023-05-16 21:55:08 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:54 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 0 hours, 43 minutes Poor (down since 2023-05-18 22:39:12 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bqro.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Xiojzztr.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Kctdyw.jsjs ace5d2a02b494b0e60477fbdd44b5dee66af462f875f0a9bd6a1f55ad5f19d86n/a 
2023-05-18Iqwvlfd.jsjs d2ecbbc4d10634ac3f47ce638df6c4302d7335ab985c09f6accdfe4df322dddeVirustotal results 36.21% 
2023-05-18Spcp.jsjs 749721b74088db119de7bccbe5cea0c9486f42bb570461ff262c5ed324b4ca16n/a 
2023-05-18Bfvw.jsjs fab89deda2e8de1afcdf4d43b713652dab42ebcad6b4eddcd3b225188a7e3078n/a Quakbot
2023-05-18Ujvzrh.jsjs 0107042269a76269dd71d3dc19e72a1759d421cbf33b9758b94f08c93f0989e6Virustotal results 32.20% 
2023-05-18Sgxpj.jsjs 41d25fd2c9445a58f5ae64b05b6042873508bfb85efe4b1b00c3c1b03c4f930bVirustotal results 27.59% 
2023-05-18Anvkjkf.jsjs 959eaab7d50ed2022fc6403b969a196f340861c5aafaa73ebd170ad225699275Virustotal results 15.52% Quakbot
2023-05-18Cfpgsri.jsjs 26e8f5245d3928df93af31946f3ff6dcf2291861ef4835e6b23e145cfcf9f8d5n/a 
2023-05-18Adhxaltt.jsjs 60ac01b6dc615a190d4fd5f4ae9e67d29d9faf9784d997dc375bf3bc5affcbe6Virustotal results 30.19% Quakbot
2023-05-18Xzfbnux.jsjs 614b789451a47511f7b28865dc84ac5a5214ce91e53b5f9ebf50cc64c5cff4d0Virustotal results 25.42% Quakbot
2023-05-17Xvxr.jsjs fb639f61394301ec51c3c82b270fa10118b12150f177db33a72560d80ad79f25n/a 
2023-05-17Clqh.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2Virustotal results 25.42% 
2023-05-17Ciztxhhr.jsjs 43f0a123b00abe19f1412b6fff2944e5bf4436a2ba20e3493ba9708ee5088c8bVirustotal results 24.14% Quakbot
2023-05-17Lbcfot.jsjs fc35a5a51f420de2456b7dcb8c59dfcfc4a5a995abb8201286aa81cd0c391508n/a Quakbot
2023-05-17Yecj.jsjs 3b367e99561731587beb5622ae151a88c15c2153723768a743a9b7f635cf1303Virustotal results 30.51% Quakbot
2023-05-17Jtvumoug.jsjs d306257143ef32e3f924f2886ed8c92b3dadea9e12e458ad402e9456a2e61edfVirustotal results 24.14% Quakbot
2023-05-17Tprrsd.jsjs 1c8c07d6d5454652a85d1673775e071cb4068ca92c83d2e45e4cf830d85e56b7n/a Quakbot
2023-05-17Ugdo.jsjs 62c77bd7e23c3a896805172ca75d452286a7a166f81f621f0d396b621ca3f708n/a Quakbot
2023-05-17Aorcm.jsjs e5b9115989505de7cec7c103ef29df9ba12eded30b69c2b35093f1a4f0b3632en/a Quakbot
2023-05-17Annisfk.jsjs 6409c10ed5a01c73117ea1f621a21e94db5b6960f7d400ec7663644ff96b4014n/a 
2023-05-17Cbexqkj.jsjs 533d4627df04fd9d687a0bc83eb22d869b5a2fe34336c094ae21f204ebe062edn/a Quakbot
2023-05-17Ndmazpu.jsjs 9af3bfbcb38c10c62196ede464b756c056663b623b927841b96b23b9ec476dabn/a Quakbot
2023-05-17Fxhrqs.jsjs d48ab0f955dd2a191d2e16b13f0c631439130d50fb57a69b9fe8ed827dec584bn/a Quakbot
2023-05-16Uvfuzrt.jsjs 80993293051300df693b06430c6fe0e15a51d2020355edc85b637a388630d8c6n/a 
2023-05-16Ycqr.jsjs 022bb82e4af23c290495fe575d68b417ec729bbf41d1da686971ce71e61c0ac5n/a Quakbot