URLhaus Database

You are currently viewing the URLhaus database entry for https://avitallevy.com/aor/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645669
URL: https://avitallevy.com/aor/?1
URL Status:Offline
Host: avitallevy.com
Date added:2023-05-30 12:09:22 UTC
Last online:2023-05-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 12:11:30 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 9 hours, 14 minutes Poor (down since 2023-05-31 21:25:56 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_C349_May_31.zipzip 5cfa581554d19b6bed65b225db29fa00d07b1248def8e97e706f1356bfc707a5Virustotal results 20.00% Quakbot
2023-05-31doc_F357_May_31.zipzip b950519c15ae900aca4d9ec301dd40551ed4c7490101e6a99a83d6834490e707n/a Quakbot
2023-05-31doc_B948_May_31.zipzip 2ed4e2ba0b08b0019b5e33da10781e6e26a51091fab7b76d1c073ed91117357bVirustotal results 20.97% Quakbot
2023-05-31doc_E489_May_31.zipzip e7a885536e6003cea015cfc05d30962f9610db5d82e659f23a5381c9e7ce83fan/a Quakbot
2023-05-31doc_B816_May_31.zipzip 2b348b235e5aa07143fe5b19f73d10ea882b9370c0a7a9b2babe68f4c08a3162n/a Quakbot
2023-05-31doc_C956_May_30.zipzip 9e4d31e92983440c12ec1c82ff1241549a73dc27b7377c9caa5fecbc96d21622Virustotal results 20.97% Quakbot
2023-05-31doc_F825_May_30.zipzip b7a4ab2d318b6f869820c110bdf99375df63f78293b2600d3f6190bc0662c05fVirustotal results 19.35% Quakbot
2023-05-31doc_F567_May_30.zipzip 0fa8e9e019848624478d8f73b22e914af54a705b3bb88b84b7e5a03c94487561Virustotal results 20.97% Quakbot
2023-05-31doc_A041_May_30.zipzip ec3bd9c040320a5ffc295b38100835ed9354039d6397f304803c6f59b6fcc8a5Virustotal results 20.00% Quakbot
2023-05-31doc_B351_May_30.zipzip 8aaee5d6d2d24ba4d27036a0d57b2b453995f67ac72348f01ddc13ac883e0ba6Virustotal results 18.03% Quakbot
2023-05-31doc_E492_May_30.zipzip 93a2e4bb29221b6c172e66c25a0569c9415dd687f447e55c8af36cc60a965035Virustotal results 18.03% Quakbot
2023-05-30doc_D034_May_30.zipzip 1bb82e8726dea297bbf2b9c63f65b057661fe7ff839167c7edfe208604e12c90Virustotal results 17.74% Quakbot
2023-05-30doc_B946_May_30.zipzip 985dba2e6be31cd2562465eb3c2d07dcde4262d9f8c5419b43dafc3a5b36c892Virustotal results 19.35% Quakbot
2023-05-30doc_E203_May_30.zipzip b9736b98094875fd3a9010b2366c00685cbb285722dc032b6f527e0d5ab814f0Virustotal results 19.35% Quakbot
2023-05-30doc_C918_May_30.zipzip d9b063f062c89fcdd1525e0d863ad7e28effef99d729bb8d1432040053f4e4abn/a Quakbot
2023-05-30doc_A172_May_30.zipzip 1b0ea04ad694d447297bc0def95108df0f0383762e9dce8b339e389932701be9n/a Quakbot
2023-05-30Cancellation 509856 May 30.jsjs 9173f333b6ce1437fe19d54b1df15dd6db6b459641bb65d1312516ed86a9c6aan/a Quakbot
2023-05-30doc_F674_May_30.zipzip 1d2062b084c5a837bec53b737893cb1d5a81d8d9d32e994da8903b43cbe95701n/a Quakbot