URLhaus Database

You are currently viewing the URLhaus database entry for https://fototunes.com/cter/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659277
URL: https://fototunes.com/cter/
URL Status:Offline
Host: fototunes.com
Date added:2023-06-13 16:33:27 UTC
Last online:2023-06-14 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 16:34:11 UTC to abuse{at}hostgator[dot]com)
Takedown time:22 hours, 3 minutes Good (down since 2023-06-14 14:38:02 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-14docu_FC078_Jun_14.zipzip 4c6caf82dd959b97718caa7061611898c3a495a680862ae0d8fb2bf8e98c3e6en/a Quakbot
2023-06-14LZJPLhTUOl0dZ.jsjs 5cd15a5947d6feb4ebe67137cdec8600bc585ff8c1343034bb040df86a0eb3c3Virustotal results 3.39% Quakbot
2023-06-144IvxQxO2IfcP.jsjs 7925ad09738164468bba03f2540cb53fb9642c59a589549a26bc7838cf55cf5dVirustotal results 0.00% Quakbot
2023-06-14Fq9BTxqpyv7HuP.jsjs 7d4299e46bc9c986cbe4daed9a9d8b7dda2879e4204d6192fb8c57bb83dc52c3Virustotal results 0.00% 
2023-06-14Loblu51Hfvc72.jsjs 6d8348cec331ee7d652dec435f1d5a3a513697040b79e3b86f268cebd42cd525Virustotal results 0.00% Quakbot
2023-06-14bXbJhzU0MQtjFs.jsjs 95f2521606f82ae3b1a8d0431a422c6b9ebb5c047ce4d8cfd9f1850b80f2cdf9Virustotal results 15.25% Quakbot
2023-06-14DA4tvVrtfSkF9.jsjs edb774ca4ce5aa0b8dd2689eecc7c5596cf5c581523fae519b269c73ae6c9710Virustotal results 0.00% Quakbot
2023-06-14otBbHGiWa8zDa.jsjs 69f93a6237243fafbd9819b0e9f48146bc2bb54273b0f7ef5815edf7b0fc9626Virustotal results 15.38% 
2023-06-14jgpBAvoF9bOl.jsjs 8e4598055189595b7b04c58a778f02457973e353989ab022f6029ad27c0b2f7fVirustotal results 15.25%Quakbot
2023-06-146PIIYTKmVUAq.jsjs 248f62597c9428bc5920ec40a1128e5954f688fb888e243ad6ff19496f2681beVirustotal results 15.25% Quakbot
2023-06-14YpDdaaCev25T8c.jsjs edb35bca2e6b45be2c59d91bb0c733b2d14862afa347aee1945f517b712cb1cbVirustotal results 16.95% Quakbot
2023-06-14quaeKzDDAMAQeI.jsjs 02c33b41cdc78e07327607670e3f4844033b51df5c18a85eb146a96c891bc4f2Virustotal results 15.25% Quakbot
2023-06-14XrCUi3s7h57d.jsjs 958342a90502bd278b7e87d0eaec2224d8b4856a579385d30092496561d6638dVirustotal results 15.25% Quakbot
2023-06-13EE22XfspgzgfbF.jsjs 59eb669a757058561ea4c07b922431289017a7bce6a4f8a1fac76b85c30ece5fVirustotal results 0.00% Quakbot
2023-06-13UfTtbE36JCVA.jsjs 8bc1f1844a4657bb065c1be165149f561eaf201471049be6bb36d44463c2de4fVirustotal results 0.00% Quakbot
2023-06-13D4Jo8TU3IuCV.jsjs bbcca37eddd3785374f00e536f7a6ab44b2d0ab8591c7e74dcc25b8409fd72a2n/a Quakbot
2023-06-13OnKAUP90XCMT.jsjs e52709cccd057f0ba8a1a15af6bd3a915c79b5304a0f9ccdbd1b4b5ef32dbec0n/a Quakbot
2023-06-13KWRmJMWN4geR.jsjs 990fcc25de370c8b28fcd7dd0c37eedff5aac1fa3c53d892528aed63d3e46499n/a Quakbot
2023-06-135NHMA6NSpeODF.jsjs 443a4858bb97867d5cd71cf4bd4fa72fd89ead7f2a7c7c54cb88492000166886n/a