URLhaus Database

You are currently viewing the URLhaus database entry for https://bibianos.com/eit/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2650150
URL: https://bibianos.com/eit/
URL Status:Offline
Host: bibianos.com
Date added:2023-06-02 11:43:29 UTC
Last online:2023-06-04 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-02 11:45:44 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 12 hours, 14 minutes Poor (down since 2023-06-04 23:59:52 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link TR USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-04document_B678_Jun_2.zipzip 2874dfa3c41b3f326e74dbebef38deb5e3fe02f3c1ba6a10af7271453e82620cVirustotal results 25.81% 
2023-06-03document_B172_Jun_2.zipzip 49933d07fbfad5f752fc47e4176f930bbbc723b626124dc6b5957e47c251b30eVirustotal results 28.33% 
2023-06-03document_F934_Jun_2.zipzip 589fe49d40aaaa3faa8fc841c41720de793c538d8f5a9afc8de05102ec7b18b0n/a 
2023-06-02document_D918_Jun_2.zipzip 8efa480a9376249009188bef2433321f77a65c6b2814c61b05b68f02ec7b9f4cVirustotal results 17.74% 
2023-06-02document_E483_Jun_2.zipzip 8d2d5dc6ef0425cb2013bc396d7ba84a27bfda28fba73151f828d82f82834542n/a Quakbot
2023-06-02document_E105_Jun_2.zipzip 2509d140abc9dac329b7042b7e800ab2d261f722779460d5072ccb575fd468e1n/a Quakbot