URLhaus Database

You are currently viewing the URLhaus database entry for https://rglobalproperties.com/sblo/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2646196
URL: https://rglobalproperties.com/sblo/?1
URL Status:Offline
Host: rglobalproperties.com
Date added:2023-05-30 16:50:30 UTC
Last online:2023-05-31 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 16:54:48 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:22 hours, 49 minutes Good (down since 2023-05-31 15:44:13 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_D904_May_31.zipzip 79b0d3473a66bbca55f03b2588e8085806e8af4c6dc84399cb836e830622e226n/a Quakbot
2023-05-31doc_B690_May_31.zipzip 57a5daf1187e8727958bcdfb6ac4740a97c58ae97846de0906be2ced218f1166n/a Quakbot
2023-05-31doc_E483_May_30.zipzip c22d5409195d10f041a19185b27493f6a3575ba2df2e050ed1917b66cf44cc25Virustotal results 19.35% Quakbot
2023-05-31doc_B537_May_30.zipzip 643659e77d117fa59ca986096eac7de826d94962fe0b003e7d677bcfc9de87e4Virustotal results 20.34% Quakbot
2023-05-31doc_E594_May_30.zipzip bdf40be1b8ae60673c58f5fa435a66ddf2ca791dbdd4a30eedc4772a6efad6f8Virustotal results 17.74% Quakbot
2023-05-31doc_A107_May_30.zipzip 672eff3bc0a9f25124c15d5cfe9e0985ce50baca66571ff9c20d10f175f2e282Virustotal results 20.97% Quakbot
2023-05-31doc_E879_May_30.zipzip 8daf194d1d96a1903fc29b31468da8185a98f9f4c7f380e8803570dad88f1a77Virustotal results 17.74% Quakbot
2023-05-31doc_C547_May_30.zipzip 75acc5fbcc8d057f021fcd5b30321e61f14dbc115e92c3e20d371788fee650f9Virustotal results 19.35% Quakbot
2023-05-30doc_B625_May_30.zipzip 6ef888caf9ddce2b3668f9dfeb97f0e24b6316a28044f6fb1446436d144b9c57Virustotal results 17.74% Quakbot
2023-05-30doc_A516_May_30.zipzip b1c573ccccdcb0a8f5be0c03200a9ba42140f103fc9cb9996e380698385b9cf1Virustotal results 19.35% Quakbot
2023-05-30doc_C316_May_30.zipzip 2aaf8ba261181a4e4ea1ed56a8f44e67fba14fc5fb9661a6dbee909a3ece158aVirustotal results 20.00% Quakbot
2023-05-30doc_B580_May_30.zipzip 28a0c879c08185735fadfad1c254593a832301af17cf612fa627dc600f9dbc3eVirustotal results 20.00% Quakbot
2023-05-30doc_C875_May_30.zipzip 36b000f6d8779a477dd4a5318c621277e26d83a7be92424ef66916cdb709a1a5n/a Quakbot