URLhaus Database

You are currently viewing the URLhaus database entry for https://maragiaexpress.com/sran/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2646484
URL: https://maragiaexpress.com/sran/?1
URL Status:Offline
Host: maragiaexpress.com
Date added:2023-05-30 16:51:01 UTC
Last online:2023-05-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 16:58:53 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 4 hours, 33 minutes Poor (down since 2023-05-31 21:32:00 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_D135_May_31.zipzip 6a9a5bf7fcc019f49fd06a8852183f50979249cb13995bbacfc0fd720af60f29Virustotal results 20.97% Quakbot
2023-05-31doc_F685_May_31.zipzip cbef526ecfef72945575f66e3a27ea5e043da2c88cb9f9bd89dd486e4f62bb97n/a Quakbot
2023-05-31doc_A987_May_31.zipzip 32c33a448d49794219dbf3364a3d816a082bac85caa850f9151f4823fd430668Virustotal results 22.95% Quakbot
2023-05-31doc_D810_May_31.zipzip 47966a553faf4b8329b780308fdd2cd95a6746ecfccd875014210048c236e1f5n/a 
2023-05-31doc_C496_May_30.zipzip 9c5dbac6625a15ae0a07b441c9fb83b1c828252b83ae62e61f9189eed3cdd2fdVirustotal results 17.74%Quakbot
2023-05-31doc_D724_May_30.zipzip 0948ca166a3b983b07409c9a86f522ace51387fd33487fd6366f6a6ce2b53e09Virustotal results 20.97% Quakbot
2023-05-31doc_F716_May_30.zipzip d25e2fa51e283263ed0d3d4b1950ce4851c7a970536b33adfd9c5be0481c38adVirustotal results 17.74% Quakbot
2023-05-31doc_A795_May_30.zipzip 4e2b1721d32db12eaead98ab6a6fc57a1fc43df0ec916b139b685d40f05ca97dVirustotal results 17.74% Quakbot
2023-05-31doc_A107_May_30.zipzip 672eff3bc0a9f25124c15d5cfe9e0985ce50baca66571ff9c20d10f175f2e282Virustotal results 20.97% Quakbot
2023-05-31doc_C659_May_30.zipzip 3225b496c4e159bf87d3697248d928ca135dc42cb4c286e4cb47e78ce6a8e86cVirustotal results 17.74% Quakbot
2023-05-31doc_B278_May_30.zipzip 5ee2d18b6d98a401b8cf9a047ef2d93386c4c67ab36fddfc75789ec5a1e61847Virustotal results 19.67% Quakbot
2023-05-30doc_F794_May_30.zipzip 6f015409ae881e08814f6aabe17dcf93a37249fd0820fa0e5f932af67848b50fVirustotal results 19.35% Quakbot
2023-05-30doc_D396_May_30.zipzip b7cd35c2ab0f1c1009f3fd07d140c3c0d98c127f9a04bd78e203bc32adb747b3Virustotal results 17.74% Quakbot
2023-05-30doc_D401_May_30.zipzip 1cfdb0b578578a3ef3ff839a46bee0b8fcf7334c6437fea1c74e7966ac6e2c61Virustotal results 17.74% Quakbot
2023-05-30doc_D259_May_30.zipzip 8cbde885b0e43bb0e4b199dff4ef27a4155b561b5e6b558e7c7a444b76e9a6ccVirustotal results 19.35% 
2023-05-30doc_A240_May_30.zipzip 1aa7b578351dba1de7d2a2c7cf2f5ac82db4e72c2f4017e9e424d2f081a6f3a0n/a Quakbot