URLhaus Database

You are currently viewing the URLhaus database entry for https://telecompunch.com/ii/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645903
URL: https://telecompunch.com/ii/?1
URL Status:Offline
Host: telecompunch.com
Date added:2023-05-30 14:42:07 UTC
Last online:2023-06-27 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-22 18:50:11 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 0 days, 13 hours, 43 minutes Bad (down since 2023-06-30 04:26:59 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-08Cancellation 225078 May 30.jsjs 1aef648b3ec04f08a93883b2655b9d23499d1a0eec36735708e5b0e59bd9ccb5Virustotal results 18.52% 
2023-06-01doc_B629_May_30.zipzip 1127f568bedbb6b89146806b412364860dee8f8278e127cae28bfe5f32476e83Virustotal results 19.35% Quakbot
2023-05-31doc_E876_May_30.zipzip 48234058b77c698dc1ffc3678f6527c03897d8a86bfa383463fd5a221b45d831Virustotal results 17.74% Quakbot
2023-05-30doc_B581_May_30.zipzip 4c0568845199654ea232495ebc8b101e511e5e941cdf5cbab4db1604ecf63dbeVirustotal results 19.35% Quakbot
2023-05-30Cancellation 597415 May 30.jsjs 2116e9a0886c9c7af1d7d1441d801231882aab114ca0e733dfea357539fd95c8n/a Quakbot