URLhaus Database

You are currently viewing the URLhaus database entry for https://mundialpinturas.com.py/ulo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659341
URL: https://mundialpinturas.com.py/ulo/
URL Status:Offline
Host: mundialpinturas.com.py
Date added:2023-06-13 17:52:13 UTC
Last online:2023-06-14 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:16 UTC to abuse{at}ovh[dot]net)
Takedown time:19 hours, 25 minutes Good (down since 2023-06-14 13:18:37 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-14mpM4gHEwPkCz.jsjs a1cc109e0f24ec62059986c929a67da7fb8f555d3a1b7c406ac3ba7a958f3fbcn/a Quakbot
2023-06-14ZduxYNbpVAGgjC.jsjs c1635e35e5061a90a5f2ed1ec06b1835ad987bdaf6cb936bd10b1eca1ee3aa84Virustotal results 0.00% Quakbot
2023-06-14uIx2kOeShWJZB6.jsjs f3e236b8fbc72f9f9fe2428b3fabe5291f5bb11d4ee4cc6f9cc8ddda8ea6bb03Virustotal results 0.00% Quakbot
2023-06-14tHtrJWsTSDWd.jsjs b536742f4c71b3e6ebd5f9c0bd7755c1b4ed815fbd0bcf3b8c1b9a8f5fa0e0d0Virustotal results 15.52% Quakbot
2023-06-14UQ0eWYPMBpuz.jsjs 804163fe4cf333a395e170201f39fb4d515021141c068615fa14e8eabd3ab3d6Virustotal results 15.25% Quakbot
2023-06-14Va1qyZOPQuov.jsjs 138d7d932fe10069e86f4f4ef46f4b9a2a9553c103eccdd6187d176149558ec4Virustotal results 0.00% Quakbot
2023-06-14Iu6ik1xLTFwtw.jsjs 4e7ae6670d4cfbf7eb507116ee2fe1dc7ff80eee0f1e442fa9453af1f4466514Virustotal results 0.00% Quakbot
2023-06-14kwIUUlGrx3cP.jsjs 58fed3a739c1ab3b03f9eeb11efae107dcb008eb920fe897eb3a9672cf263917Virustotal results 0.00%Quakbot
2023-06-146h459f8N6J4jS0.jsjs 43afb4bd253fd9d1ffa42144eee4495e871bd9112db17c6d4f544fe8cc8b7c0eVirustotal results 0.00% Quakbot
2023-06-14cmHIO5MbXKhvFN.jsjs 0421037bf8c72cea0d5d21c7ec0f9f227fcba9064c67c688f774a110943abfe5Virustotal results 0.00%Quakbot
2023-06-14V4W7Hf5zwlDL17.jsjs 2a406608a0ffaba2656cf5879e23dfbe00108787515fb0cf28a1f28ba8b06c94Virustotal results 1.69%Quakbot
2023-06-14ZTBmezckK5Cp9.jsjs 77ee59f5de41fe253695de13801bf06c13dedc1897fa9fb15b5b6e0635c2455bVirustotal results 0.00% Quakbot
2023-06-13D4Jo8TU3IuCV.jsjs bbcca37eddd3785374f00e536f7a6ab44b2d0ab8591c7e74dcc25b8409fd72a2Virustotal results 0.00% Quakbot
2023-06-13U5eMkRL6CbFETE.jsjs 4573e411b70a42868e2b1d62ebddb99005c241abae8eb6652d2e1d1e3b815681n/a Quakbot
2023-06-131UHhIus9qgKD2Q.jsjs 78dd958ee9636a38c8d84a90a51fcc345fe95612819d50fd52ee4c90194718c9n/a Quakbot
2023-06-13V0HdWsxTeHez3.jsjs e43fce049074b91782ec0c826b7ce89402dfed3053e23b15d8472264b63ebbc8n/aQuakbot
2023-06-13E59vOxgBFvstc.jsjs 24f2158bf5aab157264c1a1f1a2b13476744dd44b9c41d9de0728b2b68845956n/a Quakbot