URLhaus Database

You are currently viewing the URLhaus database entry for https://cozailorinqc.com/tt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659238
URL: https://cozailorinqc.com/tt/
URL Status:Offline
Host: cozailorinqc.com
Date added:2023-06-13 16:33:15 UTC
Last online:2023-06-14 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 16:34:09 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 0 hours, 48 minutes Poor (down since 2023-06-14 17:22:32 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-14j6Z33YeRK0qO.jsjs 2a260768e2beebcc1da2d3368064660d054fbe8aa002eee7f2d9555f2340380bVirustotal results 0.00% 
2023-06-14NbhLFskkEuB6b.jsjs 48eb2e68946564c7e368154c0bfd50d784f690ea037f14bd8dbc98e21c830452n/a 
2023-06-14docu_AB509_Jun_14.zipzip d36757a37cfad9dd9bce6ae6b436978344bfdeeac399a3f7bf4ef784029c9757n/a Quakbot
2023-06-14EH0pOF5Y6oaW.jsjs 936aa95b1bcbffdab0d7e7e4b07b4ffa3907500bc9ac96a5d879d85aa64ffe9bVirustotal results 0.00% Quakbot
2023-06-14uQ2TFNzOMgl7D.jsjs 5c4e49c1977a1a6350d56c77e09bf00d527cf459ffc47c665697c3cf349bf90aVirustotal results 1.69% Quakbot
2023-06-14aOEkRE2A2Uyx.jsjs abea42c24e68ab1dfce9c66e1d510c5a7fb59c47ebfce07b2108bfa4829dea83Virustotal results 0.00% Quakbot
2023-06-14LuTEqhaKztlUy.jsjs 768c7f7dd8a5c0704094fe92cc77d3d667040c32f88658005ea1730725376bfdVirustotal results 0.00% Quakbot
2023-06-14Vba0fW4B286EB.jsjs 319976befbb5269faeb1456a5aa2380505f358c976f911c341cfdcabc7981a1cVirustotal results 15.25% Quakbot
2023-06-14rrD60uX7OcAa1.jsjs 3a3f6e894d8cb08e67dcdadda77cb165936a1a368e91300460d145f3fd09b4ccVirustotal results 15.25% Quakbot
2023-06-14OnKAUP90XCMT.jsjs e52709cccd057f0ba8a1a15af6bd3a915c79b5304a0f9ccdbd1b4b5ef32dbec0Virustotal results 0.00% Quakbot
2023-06-14Md175YlLRr2i.jsjs c72f9d4985280477c1b57234ed6fdb9d760060d765c03db312c206ea35e8cb98Virustotal results 1.69% Quakbot
2023-06-14c7uTjOcvUCN3I.jsjs 660ff12604e28d9e2c91a490f5d055fbe152df411d179df1578c9d54b875c06cVirustotal results 0.00% Quakbot
2023-06-14qQPNdkvTiDdwNs.jsjs e7cd21fc50018e3a9d2df41a2c343698e595a11ac49619bbf9d7aaf657545e65Virustotal results 15.25% Quakbot
2023-06-14VCS6wRRz5XxZ.jsjs dc380c6947c5f8de2586ab7baf30b36b6a9426932323cb2096af2c5f4e2c344dVirustotal results 15.25%Quakbot
2023-06-13UVc4VkYwzoaHq.jsjs bd23dc61662cac8005b92f5bd9df881de1391cca73e36e749f5eaf4e8e53bd11Virustotal results 0.00% Quakbot
2023-06-13wcVt0SlN4jXkZ.jsjs f1da51711fec5288c298f706f7d6ea9323c81c167bd258ff00f5810d1eaa2497Virustotal results 0.00% Quakbot
2023-06-13W2I4jd9Ysv5XC9.jsjs 48f7a827ce26700fb4fc4370955e762fa9944d462d5c8ec894f100ed6a1286a1n/a Quakbot
2023-06-13XrCUi3s7h57d.jsjs 958342a90502bd278b7e87d0eaec2224d8b4856a579385d30092496561d6638dn/a Quakbot
2023-06-13E59vOxgBFvstc.jsjs 24f2158bf5aab157264c1a1f1a2b13476744dd44b9c41d9de0728b2b68845956n/a Quakbot
2023-06-132DCxkYC8wSAVH.jsjs fd17cd463af9bf449d3eb07975e3ec381c8a7608011d1e56b64d01ce8c363dbbn/a Quakbot