URLhaus Database

You are currently viewing the URLhaus database entry for https://salesoxigen.com/ouu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2650095
URL: https://salesoxigen.com/ouu/
URL Status:Offline
Host: salesoxigen.com
Date added:2023-06-02 11:43:13 UTC
Last online:2023-06-05 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100126969 created on 2023-06-02 11:44:04 UTC)
Takedown time:2 days, 12 hours, 18 minutes Poor (down since 2023-06-05 00:02:29 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link TR USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-04document_B710_Jun_2.zipzip e84726c15a1cd5716f71c27bb6c65a42c75421b1dd15b6fd8a24be24c4db4333Virustotal results 20.97% 
2023-06-03document_C471_Jun_2.zipzip 0b7dbb099fa83022597ad8c0c39b469ad28c685b1e68ee3b399753f7aabe74b8n/a 
2023-06-03document_A127_Jun_2.zipzip 4181745404995564385ec5798bf73216b0fc138c7ba6fdfc9c8f1a6c2d72eb77Virustotal results 25.81% 
2023-06-02document_E243_Jun_2.zipzip 7eda9d43c86fd79205472a3f6004d08917ec2cddd2e0340d30814f2ea0b1019dn/a 
2023-06-02document_F924_Jun_2.zipzip 5ece82a89c6cfe8b21bed7cb83d3886e88cc01d1efc8a13bb6984cd559a013dcn/a Quakbot
2023-06-02document_D590_Jun_2.zipzip 4eba615c80f9d4d51fdbfa84dc793fa109b11b7b8ca8ed9cbfc733baeb8bf26an/a Quakbot