URLhaus Database

You are currently viewing the URLhaus database entry for https://ecotasar.com/amuo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2649251
URL: https://ecotasar.com/amuo/
URL Status:Offline
Host: ecotasar.com
Date added:2023-06-01 17:07:14 UTC
Last online:2023-06-02 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100126474 created on 2023-06-01 17:08:11 UTC)
Takedown time:15 hours, 40 minutes Good (down since 2023-06-02 08:48:53 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-02document_C812_Jun_1.zipzip 787889b0936e6c00d2b0aa5a5ffec1159256cb0c9039a27f6c140394abd000d7Virustotal results 19.35% Quakbot
2023-06-02document_B520_Jun_1.zipzip d1422db58b813ae533225360c6a08420ffc9b39e8b644783a397d57ac40b6c21Virustotal results 20.97% Quakbot
2023-06-02document_B403_Jun_1.zipzip fb8b2d3f295d46bf2304bf41e54fa2b6b52866df8fed1d48d679889b89d00f60Virustotal results 20.97% Quakbot
2023-06-02document_E617_Jun_1.zipzip 2711384183b821de0dccaa2727da95ff8a77b88cac160dbce0ba53287e99b884Virustotal results 20.97% Quakbot
2023-06-02document_A207_Jun_1.zipzip 6480bb2cab7ac93f688719c45c0fcdb9773612d0a4b61741c0276910b2652486Virustotal results 23.33% Quakbot
2023-06-02document_A012_Jun_1.zipzip 0e4322df2d93a9d4e6572dad38ee7a65b674350ff04ee7b390e0c5098b5f103dVirustotal results 22.58% Quakbot
2023-06-01document_A372_Jun_1.zipzip d3e0825c74b4383a1f3b4175715135c5dc49565a4600588e65f3b0167c0ee99eVirustotal results 21.31% Quakbot
2023-06-01document_A365_Jun_1.zipzip 5c872cd4fc4836eee4764b57285bfba04a9de1cb04ce138ec6218a7034890503Virustotal results 21.67% Quakbot
2023-06-01document_E289_Jun_1.zipzip b040dbe802685c352c4867be77dcd6b3e5ad52bbc00e15099bf81f29ad26a478Virustotal results 20.97% Quakbot
2023-06-01document_A916_Jun_1.zipzip eb598950ee6abd7471cf945b3483e32beb636348a8a2a5432065733e2f35e1beVirustotal results 21.67% Quakbot
2023-06-01document_E062_Jun_1.zipzip c2bd611aec129d88745345f91b586dab1da45e3d7f64ca721bd32f940bc486e3Virustotal results 20.97% Quakbot
2023-06-01document_C096_Jun_1.zipzip 22d294c758642e998cebc8728ad2f3ee46cd226d4243661a5a2f55b557c56a78Virustotal results 20.97% Quakbot