URLhaus Database

You are currently viewing the URLhaus database entry for https://studiolegaledefenu.it/ag/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635646
URL: https://studiolegaledefenu.it/ag/?1
URL Status:Offline
Host: studiolegaledefenu.it
Date added:2023-05-17 13:06:13 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:42 UTC to abuse{at}serverplan[dot]com)
Takedown time:2 days, 8 hours, 8 minutes Poor (down since 2023-05-19 21:17:34 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Dyuxxtk.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 25.42% 
2023-05-19Wjyrb.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-19Uwwui.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 25.42% 
2023-05-19Hiqxhknl.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Tvfqj.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Dwjorcw.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Lyyeindh.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Zwyqg.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Wbdy.jsjs 815c6875a6b1118564a791b39421dc1277354558c640dc554b130a9664a0663bn/a 
2023-05-18Hcbmdz.jsjs dd72eab3dc3f67fee1ec6cae276e3ecb4fd364daf45f773c22f8a0c771fbf742Virustotal results 25.86% Quakbot
2023-05-18Xqcxwpb.jsjs b7a9d786648f1049f8c0964593b9fa3983e6066f5674ff98d438cf5ec9d592f4n/a Quakbot
2023-05-18Ebdyhgqj.jsjs 33f33ebc5ae78bdbf3a9afc064c64f1121c0214e1305d5567232cbc8779ab8c3n/a Quakbot
2023-05-18Qoeeea.jsjs 2570cf55120f499263bb8841172328a59101385bd1804bb919458e9bf167319bVirustotal results 25.86% Quakbot
2023-05-18Slxfrmf.jsjs d8227132d7300d02c5cf46a7c7c4ea76a6fcd10c516382dad0a8892266612025n/a Quakbot
2023-05-18Wgod.jsjs 106ea6e9df2db6267999fa9df4ae5950c1be2de07cbb773cd739bfaa29a806d4n/a Quakbot
2023-05-18Gxupul.jsjs 817e3087dd09d826cc20a0381d67784b264c51a854134ac760b9219f49d58f0dn/a 
2023-05-18Hdfegvh.jsjs 62046b91a066c98a15aeba46b02ff8ae453c2d23d8e39a7e7eb2fb4d322464cfVirustotal results 27.59% Quakbot
2023-05-17Toxeir.jsjs 6f741f3bd19d3433e0618cd31b85f73aa09fb1dfe670c9e5a8e0ec01cf274495n/a Quakbot
2023-05-17Fdkr.jsjs 6f1a5f81c661643e1367ba7f42de50ede7d8841c0eb4bd7e13f5922b8a539766Virustotal results 29.31% Quakbot
2023-05-17Ldcs.jsjs c56bdfe438e6261fa00e5e48e3e9896927886b959c2947db67582b4cf0f08e74Virustotal results 22.03% Quakbot
2023-05-17Bfzondiy.jsjs 4cfd3cea6e5aacf340993648b46bbd6628953021cc5148be665b68de39755e98Virustotal results 27.12% 
2023-05-17Nxfnv.jsjs b866fb32a73c9c9a6de4c2fa92651d4d8d7f72f0fe66af797867274e8a889e85n/a Quakbot
2023-05-17Nlmvabfm.jsjs 6ee195c06baf35069572750e08cf581ee2a7a59c0b75faff8c5284a839f34ee6n/a 
2023-05-17Bqnylpeo.jsjs f744aaa7347e22e22b0047605341e57c431a9dbcdd028ca5713a221c51107aa1n/a Quakbot