URLhaus Database

You are currently viewing the URLhaus database entry for https://gaiaauto.it/xmd/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2646050
URL: https://gaiaauto.it/xmd/?1
URL Status:Offline
Host: gaiaauto.it
Date added:2023-05-30 16:50:10 UTC
Last online:2023-05-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 16:52:32 UTC to abuse{at}serverplan[dot]com)
Takedown time:1 day, 4 hours, 47 minutes Poor (down since 2023-05-31 21:40:03 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_C369_May_31.zipzip 2eaa757b311618aad086e43c229e58cfa4bf5729497d23feffe0ae0268ad7a38Virustotal results 24.00% Quakbot
2023-05-31doc_F921_May_31.zipzip eaa157642118c7c08be8c0189eca0ea8b554f09b91be79a46f24373f814f6a68n/a Quakbot
2023-05-31doc_C153_May_31.zipzip d5469b9eb3be78c131bf98b47a55a8707b9b9854c80e4b9f56b6dc210797e9f9Virustotal results 24.59% Quakbot
2023-05-31doc_B869_May_31.zipzip 023361ae3aadd6ab0f38292c2b4e691cd1decc93e0f0c6630476af831d7e8e36Virustotal results 23.33% Quakbot
2023-05-31doc_D218_May_31.zipzip 7d41c982e4e0acebdab7eed810995e295e5a36811cc3a4b94d4cf8c186c39638n/a Quakbot
2023-05-31doc_E657_May_30.zipzip 8df2ffe7b18e0ba364650e8fdc5197ffb992b5d49ec1a23c96646a856e5615a2Virustotal results 17.74% Quakbot
2023-05-31doc_E641_May_30.zipzip 7b9732c887e5a20b342ea3c0478f0b75648243a6c9a691ec22bf1ef71213fbf2Virustotal results 19.35% Quakbot
2023-05-31doc_D281_May_30.zipzip ff489fd8dbd188cd4b300827b89e194f277f628c06da66939038667b0d3f3b74Virustotal results 19.35% Quakbot
2023-05-31doc_E785_May_30.zipzip 03454b2938c634094cc0d3d44704d499ba300f925581b4207c024b8563510fc2Virustotal results 17.74% Quakbot
2023-05-31doc_B527_May_30.zipzip 3e78f2b3ffeef6fdc56a8cd5ccad7336a67bd32cbb127c2bebfe95f5024ebba2Virustotal results 16.39% Quakbot
2023-05-31doc_E518_May_30.zipzip fffc0acf4db3eff61b5a998ce826872fe60a54aee35c152b806bd8d914022d93Virustotal results 17.74% Quakbot
2023-05-30doc_C017_May_30.zipzip cadf612a03deb428e5a63fc7062d3c1f776ce82ea994d926c3e9dd93863039c0Virustotal results 18.03% Quakbot
2023-05-30doc_C365_May_30.zipzip 181a677ed1dd30f356c44c000b847826808a92890d67f6aea88ff58e8f6fb0aaVirustotal results 17.74% Quakbot
2023-05-30doc_E970_May_30.zipzip 78cc4f4c003d63bd6ddce3d1eca5bb733a54d3095c5acfc23cba32796d79a2a7n/a Quakbot
2023-05-30doc_B852_May_30.zipzip 222ebab8461e6a6114a4cb214e76fb36dffbda528dd97a81b6602cdc67ea41f6Virustotal results 19.35% Quakbot