URLhaus Database

You are currently viewing the URLhaus database entry for https://grupoalvez.com/net/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659247
URL: https://grupoalvez.com/net/
URL Status:Offline
Host: grupoalvez.com
Date added:2023-06-13 16:33:16 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 16:34:20 UTC to abuse{at}tierpoint[dot]com)
Takedown time:1 day, 23 hours, 27 minutes Poor (down since 2023-06-15 16:01:44 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AE637_Jun_15.zipzip 68024f3a0f3327957b823c3de9415207804e77b731c69632a7b0bdc1905addbbVirustotal results 6.45% Quakbot
2023-06-15document_CD804_Jun_15.zipzip 49796de5fe0d580af9be1f71f6b43300f30bd4042ebff79ef919d3c640edae0fn/a Quakbot
2023-06-15NvD8itIqNSSLj.jsjs 214a41894bc66a12cf05a87a62c9e290c1324c51558cd8f63b4096fe75ad1cb5Virustotal results 15.25% 
2023-06-15o0wNx0mowAheM.jsjs 6ffbe5a82b8827796d3974e17596e8fa43db3c579bb21e84887ce065145e34bbn/a Quakbot
2023-06-15NtSro8fHx4hf2p.jsjs 837f19b5e3bbdd8213694b8bf6ace33cf991afa8f7febc3377a1b6d92cf2222cn/a Quakbot
2023-06-15CPwcxmnCxEzWYs.jsjs 643b17141fae317ca933669dbe31a07c37efdea2d30db65dc5e2dc47fb7bc9cdn/a 
2023-06-15weic21tAav44.jsjs 9e93ddbe1f77f7e8cc11348e9e0c3ed0f575a1932233be94e214ad1f58092557Virustotal results 0.00% Quakbot
2023-06-14docu_DA051_Jun_14.zipzip 26142a0f5c45d89a419cb74804c79a35b83fd70369f811a8c9f15807a195022cn/a Quakbot
2023-06-148NBpht0CPmrJP.jsjs e67cc251b0099e6448533274e9bbee0b22390af8c47a92bb6c7fd8fbd5725285Virustotal results 0.00% Quakbot
2023-06-14wGPLf6J1zy0HUP.jsjs 58a104218ed7ece5c31800e1f1fdc76882c4f6a6009bee726a54579874e99460Virustotal results 0.00% 
2023-06-14GXPgFanLnGVg7P.jsjs e07aac140a5b7d449d59bfccf9fca6c1632f2cac507a68d673a96536b797d682Virustotal results 0.00% Quakbot
2023-06-14EGlKdomTlEaOGK.jsjs c25ecf652174f94ac18bba8177d5d8322fb31d649edabc523b505e815cc47376Virustotal results 15.25% Quakbot
2023-06-14Qn7DqtRNohDm.jsjs 9f3de48d50ae11c8416b11db22eca5f04706871ac6c58bc9ab556b5947e3ab55Virustotal results 0.00% Quakbot
2023-06-14SyluCEzqroQN.jsjs 3f65fb92383f4ba551003b030280c3b28855834ecd6b3228a73ef2b96616f6e3Virustotal results 0.00% Quakbot
2023-06-14YWZvorgC9Vw4H.jsjs 8a9f624cffd86aa962676fc64c27678aeca0fad692090a9c3ff88ef85ca254b5Virustotal results 0.00%Quakbot
2023-06-14nmV4mshfVwKnFB.jsjs 784399d6d2e3875a39ca8acaabbdc39a65ab09bb8ae606316725238361ff2257Virustotal results 1.69% Quakbot
2023-06-14zf1jhxsialVf1.jsjs 6594b566b5566f81e8f739e53376fc4ee265475050a4df72fe32e8dcc8f1bdbcn/a Quakbot
2023-06-14uxRIFAgje21o.jsjs 8670dee51f9e9588f77e0da71d324085bd9f779001244b568f807e6e24782340Virustotal results 15.25% Quakbot
2023-06-14qYs8hxxVxEYHXx.jsjs 53619f4cda3f568df90f232752b3312b12b3b4f48e9a954049b852674bc7b778n/a Quakbot
2023-06-14ZZrvn6j1TCC6c.jsjs 5a652761cdc46fb64dfac6c2d3d9ab2bd6108ccef5860b411746c8de1c6ccf59Virustotal results 0.00%
2023-06-13Qvp9KA6vRsxre.jsjs bb8759ef43fe68f47088825593a27fefe39693d115e9935c8d7c14201e0ac965Virustotal results 0.00%Quakbot
2023-06-13D253kT2CkUr6NF.jsjs 6d2348041be986c102d77a8aedf90af383d61b6eefacda967a38137fb09022a7Virustotal results 15.52% 
2023-06-13d2NckNLiL6A3DM.jsjs 442d04dbd9207f2e4b160299998f61debb7474325fda8ea88a4e85ed33fb994cn/a Quakbot
2023-06-13injZLE7q3xpsT.jsjs 8b0945c51b038dd1ce17c6b4dee9353fc9cab765d79552c0bd30489d11f012bfn/aQuakbot
2023-06-132NUyuWbsUnLyR.jsjs 285bbd470f02823a6192916c89104201e7262d1658c85ddd2fbc37e45ef23cadn/a Quakbot