URLhaus Database

You are currently viewing the URLhaus database entry for https://rucero.com/qoas/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659255
URL: https://rucero.com/qoas/
URL Status:Offline
Host: rucero.com
Date added:2023-06-13 16:33:17 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 16:34:28 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 23 hours, 48 minutes Poor (down since 2023-06-15 16:22:51 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CF495_Jun_15.zipzip 629dcb048169554b71c6d2a10df8ee5bb704b299809e871b4777c51776d6d03bn/a Quakbot
2023-06-15document_BA453_Jun_15.zipzip 12fe6fc7fec632cb58f53035c362e3fc7b367936335216ee14bbc4cba751ee9bn/a Quakbot
2023-06-15hUd8WmEEfh7u.jsjs ab39ef32f5dfd764a20d19c5128c8ae47f3b3ec2f150085d9224c71175fab381n/a Quakbot
2023-06-15RSe9aTXm5MsW.jsjs 252ea0d350f4385527136455d4b48387482f588ce62510d85ea01552ed1963efn/a 
2023-06-15UQnQ9W94MRPY.jsjs 1f3621525e93f1478476b43570187fe662487bef8f8eae8aa31bfd02677cf744n/a 
2023-06-15gr29Kvb0Yph8XW.jsjs eed7244bb5aa79f8c067de70617549185fdc5687e3ca6603b24c5698f0fc1fban/a Quakbot
2023-06-15vQppChNnTMWYQ.jsjs ca5b6af0afa345bc0e3a79fa2ed19747998b4c4e7b76c164343c28f0968ac223Virustotal results 0.00% Quakbot
2023-06-15pgKgnxjhtIuY.jsjs 8b69b2a765d237d79ed128ec38a4e471222e43c528689953c7029423680bd209Virustotal results 0.00% 
2023-06-14jusoIxwiz9BFTC.jsjs b03ad3cfc399625de2aa0a35a1d535f13ac90836dcc294b9012940be3958d6beVirustotal results 0.00% Quakbot
2023-06-14docu_FB725_Jun_14.zipzip a861d18c7fad50cd214bc1cf255bfa21ddb1c7f18a4439a65f2d9cec2511bbe7n/a 
2023-06-14docu_CD378_Jun_14.zipzip aa071006010c64ed700fbecfebee04dc13018c1c50b72d71fd49fd7fdcdef239n/a 
2023-06-14docu_EF925_Jun_14.zipzip 10e566dcc281e6b991c1793ec7bb7fcf5340ff7c607fbc94780502a1567b8bc0n/a Quakbot
2023-06-14OS3NR3Q073Bc0.jsjs 320b00d1b37b326c3ea175b31ab2f6c06d6da56545c455c1570eb902cc3946a6Virustotal results 15.25%Quakbot
2023-06-14CcsOYGG44qXNG.jsjs 52f54d4a6c88107199433176af59ae6d6b3511b2ef89db4393bd8c6aa60c8ec3Virustotal results 0.00% Quakbot
2023-06-14KZDu4HpzfY60a.jsjs 0b45bec0aa6e9d9969b6be347fac28fbfeac0102e552da0dc28e362f32c60f81Virustotal results 1.69% Quakbot
2023-06-14fv82YKCx4m5IMT.jsjs d9c252bff6eda77d590cc25382534d315921058f11abf5fd8cede81804f89ec9Virustotal results 0.00% 
2023-06-14Qvp9KA6vRsxre.jsjs bb8759ef43fe68f47088825593a27fefe39693d115e9935c8d7c14201e0ac965Virustotal results 0.00%Quakbot
2023-06-14wPp9qkCLyekH.jsjs 464c74537ba1bd496d16ec9e88e01ca229415c26546def5b995060828da4e6bcVirustotal results 1.69% 
2023-06-14g7oMUPzhllj4.jsjs d835fbf3654c7b0a2fe8de58cf8545880abcfbe6997bda462ac909881963238bn/a Quakbot
2023-06-14YWZvorgC9Vw4H.jsjs 8a9f624cffd86aa962676fc64c27678aeca0fad692090a9c3ff88ef85ca254b5Virustotal results 0.00%Quakbot
2023-06-14tDSIPtjiHVjMI.jsjs c7b1f5bdba77ee38d49324f1e11eeafc16f5c6d58fb0f12be4290708730b5765Virustotal results 15.25% 
2023-06-139eYWev6IJ6HDKZ.jsjs 8d0c5230e3e77fb85e7309a25323377f13e63474974afe8d5abcb0260e8fb186n/a Quakbot
2023-06-13StjLYl0ZV4wgpy.jsjs bc7f8a0c0173cdb7fe20372bc4ed888006702d7882dd8a12d619afd70fbf1024Virustotal results 0.00%Quakbot
2023-06-13Ml4hvQkhDvZWyU.jsjs e4cf202a4c3099e2f738faa5bc3836539b663d89cac1bb53e3e26c26bee1336cVirustotal results 15.25% Quakbot
2023-06-13ZU6X7uFnLfON.jsjs 08fcba4bd4294f71d9703bdfde10ef905083c55eb4288959983ed7e7dd2b0d18n/aQuakbot
2023-06-13ZTBmezckK5Cp9.jsjs 77ee59f5de41fe253695de13801bf06c13dedc1897fa9fb15b5b6e0635c2455bn/a Quakbot
2023-06-136PIIYTKmVUAq.jsjs 248f62597c9428bc5920ec40a1128e5954f688fb888e243ad6ff19496f2681ben/a Quakbot
2023-06-133fDNbmg8kqzK.jsjs c02d10872cba0d9ea47cc36cd92a6784bfbe334c1ff1386886cd6c9b5bca6061n/a Quakbot