URLhaus Database

You are currently viewing the URLhaus database entry for https://stefanicarvalho.com/liou/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635097
URL: https://stefanicarvalho.com/liou/?1
URL Status:Offline
Host: stefanicarvalho.com
Date added:2023-05-16 22:00:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:02:01 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 23 hours, 34 minutes Poor (down since 2023-05-18 21:36:12 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Idadxoiq.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Nnex.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Qpeivfed.jsjs e21240cb74bd3c60d04aefb9d6e4386ac8f7852cb0685bcca31dd717c6f2ce96n/a 
2023-05-18Gmzucgp.jsjs 90854b60ab6b30c83f8839a6d1977dc7968771625bc4a6751d30fa1ff505912bVirustotal results 27.12% Quakbot
2023-05-18Whapasfk.jsjs 939b394768f864f5af2b1e196cb9982563bcbf1157f23f9a873030ba262566c3n/a Quakbot
2023-05-18Fzarz.jsjs 345e76a5091b5ecf319a57a8901fc203f48dae4dcc62b70fdc4d1e542d1a1f46Virustotal results 30.51% Quakbot
2023-05-18Wvhkz.jsjs 34af4640c3591095a1562606faa096b2cab669c17859f8b99df4321999b17373Virustotal results 22.41% Quakbot
2023-05-18Xisoajbq.jsjs b45fa98328f6170801cd88be88f4ac670f2266e2ed383e78f37fdd5d860dc695Virustotal results 30.51% Quakbot
2023-05-18Vmeghca.jsjs 16caea9932a7ec64a3898dc621d943071edcafd1ebf99fcda24e82ab6aa52733n/a 
2023-05-18Cbtbepy.jsjs 47b6986c5352ef5a3ecf9cbe02d34caf8e096cb6635c958ce8dedb89540da3d8Virustotal results 26.79% Quakbot
2023-05-18Kgbin.jsjs e0a76560e4dfa1a02a0ed9070737950e644f0b851388f7a580a8c384ba1ae3aaVirustotal results 28.81% 
2023-05-17Glzevx.jsjs 245d8b4566da1f99cc5bba4998955421b38764ee0718c94a6fe8019674ccfcd1Virustotal results 27.12% Quakbot
2023-05-17Oikg.jsjs a357a8a9b62674cff6660b76659f4cd36ccd979d44937371bde57235d81c392en/a Quakbot
2023-05-17Iqmxw.jsjs b88c04bb3bdf213453514ee3d92c8a7fd5f5e014017ea615f8df49c9c0a7ebefVirustotal results 27.12% 
2023-05-17Sosspzi.jsjs 47f14a8b9c04f43e700eff818ff6490f28ae0bcba08118d1af9f0b06c96779a1Virustotal results 29.31% 
2023-05-17Pxmotsbl.jsjs 9898858b1809b1511e09fbef76498bfa2d39365eb70958ac81ba4a0263c6e209n/a Quakbot
2023-05-17Gljjd.jsjs b4bbe3eb6f77c745b1c296728e15c69c6b766df2aa51d6d745ce4e5fee415e06n/a 
2023-05-17Bxxznfu.jsjs ff50e9d6bada1c148165cd94d8242cd7c0651692a508bbec763046c0ad17be90n/a Quakbot
2023-05-17Nclmouo.jsjs fcdd7c512aa91e5f6574a7c7ab77a118b9e1af5f2e3b502a5adb136508c4ba47n/a Quakbot
2023-05-17Lcnpl.jsjs 0f29eeb72c1a234e0ef88f7a250a522198df361a808c6e31760ca4d25e8c7530n/a Quakbot
2023-05-17Dyvvpalf.jsjs def8f1f1fa9cf6b75fd8cb80145632dcf77a583c49c7beb8dac9ec67146b760an/a Quakbot
2023-05-17Uvxwfsv.jsjs ffee0e9ddb0e713f4e8e454272d3ecbc18b51062f855d3071ac7ffe6cd329db0n/a Quakbot
2023-05-17Elxcspjk.jsjs 3a980f873c20951dac26d8075b838919e2aa73d80c0bb06b66bce4fe54acf59bn/a Quakbot
2023-05-17Suzpity.jsjs 9c5a0576c1f4b3ad23fd86b8fcce0d1dac8fd344dcbdbc374fa24fccb1e72549n/a Quakbot
2023-05-17Chsyuyu.jsjs 7951f0a6c1982907265f3ac04824b8745014ef3e6a913866241087aae5db9dc4n/a Quakbot
2023-05-16Djzcau.jsjs 617409a03fdfdfb2642d5deb1387b414098aaa90b19be8d5ff4bed1dede1fae3n/a 
2023-05-16Xqdslaid.jsjs 457db6e54f690bf59ac728a31b1221190318dc57201e8e657483df4a21b76ef8n/a Quakbot