URLhaus Database

You are currently viewing the URLhaus database entry for https://paulof.com.br/ee/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659348
URL: https://paulof.com.br/ee/
URL Status:Offline
Host: paulof.com.br
Date added:2023-06-13 17:52:14 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:25 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 22 hours, 1 minutes Poor (down since 2023-06-15 15:54:48 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BA621_Jun_15.zipzip f2d7595840d3d7d500775deae10dcca6eb7f5ffc8b39db593ec07792b5809600n/a 
2023-06-15document_EA193_Jun_15.zipzip 57b2a482b848d9da6fac0363cabf3d90f397a9495071e417a3734c3bd9f3cbcbn/a Quakbot
2023-06-15m08c5l0j2Rpsz.jsjs 600e7a625fe321590ac2bf6928bab149529a54eda8dd623d52eb437ef71479edn/a Quakbot
2023-06-158kvOqJqlla5M.jsjs 8f902275d63e5206a9b98ba46357939247f6de506b93c76fd2c28581e1eb0e94n/a Quakbot
2023-06-1522laPeHEqU79.jsjs f9785ae0225d3ab5cf172602ad9f66ae945217ee8b128a43fab87c589efc04aen/a 
2023-06-15OEdtkGh65mueg.jsjs d33cdb366bd134caa1796ac5679a62f6d4da7f2cb9d556e18b4be620ff9744e0Virustotal results 16.95% 
2023-06-15CTpv12CF6Lm3mV.jsjs 366a631017ed173b9a4b4b8c89e35f4b1a01ba68e18b8a6295682c05519bfc14Virustotal results 10.53% Quakbot
2023-06-1415Y3OkStgb7s.jsjs 6fd5a5d2d3c388f057d635cbb379d124c48cc7a66f943d2788ef3851f95022d5n/a Quakbot
2023-06-14PihOhjd9WYNGKx.jsjs 6a6bee97fabcc123f584f7f3209bc48e2b27ef2d0609cce16ee583771f0b6c80Virustotal results 0.00% Quakbot
2023-06-14nHbI1t2nrFIJzT.jsjs c4d67e01714e14f46603e0e760ac501063f32afe5e6e2365742f3aa9ba1779f9n/a Quakbot
2023-06-149VxF0yKaLewQR.jsjs 6a9f9be0ee02c85b6624b531f1a7e0d25684318747c3046b1386d83c01843098n/a Quakbot
2023-06-14KqSLwjCmQQ2p.jsjs 2932accaf419737fe7893701457ed834ad17fbad8b735b46d8ae62b25ac88291Virustotal results 0.00% 
2023-06-1413ihSzMUcQru.jsjs b3a7e8f31b81630441591ae2a1e5693d483de48928c5cfc0c1db83188c6be4eeVirustotal results 1.69% Quakbot
2023-06-14w3T5J32Yllk7h.jsjs 83be82e378dd748cecb0dea28355fe79c5ff4ce98045dc4022284dac40bcaf16Virustotal results 0.00% Quakbot
2023-06-14L9zLS3kG2hRVF9.jsjs a65d05999b9e84c699e8cce7c926554e78a0d71daa1acb64ed8fe4e344a67f40Virustotal results 17.24% Quakbot
2023-06-14ayUXN3phOf3coX.jsjs 726a7ea1923ffa5c7fc0dca35ad4a8149150adbb1632148d0a8811147967fa66Virustotal results 15.52%
2023-06-14QBS1j3HXRwkf.jsjs 52d7a3eb1a87e1844d40bddb7c30f0a99000d0e5aa997c8e2b458821bc79f123Virustotal results 0.00%Quakbot
2023-06-14eEOLEua7yhWR.jsjs aa798bd878f345c7a7a24acc5dd5e5128d8ba0ac3ce8b1c9fdc4b4c34a5e7639Virustotal results 1.72%Quakbot
2023-06-14Q35v68sDwWWV.jsjs 3bda63a1f8c60521a0d35aa8c567de92bad4caa26a67b10f9c32a40f7498fb44Virustotal results 15.25%Quakbot
2023-06-14UMCcwr2a6Rvz.jsjs 1b64c00768c6add77bc652b656bb85be65d2b30e8af0bbb96515146e20b6e9c6Virustotal results 0.00%Quakbot
2023-06-14yFy8hTaF6YxL.jsjs c1fc786f49fbd7feaf3d3e406ed46c39a0f8a65dad1e744e91ca2f2f739c4727Virustotal results 15.25% Quakbot
2023-06-13ARUAQUPRJfFYcL.jsjs 438c5dc253fcb2627ed01f0a8d74730ba02a30049b4218b013dbfc3d33b93880Virustotal results 0.00% Quakbot
2023-06-13sDTJ4y23w2iN.jsjs 429f40203cb0309daa8ae8225006da50beaf1618be71766fade353cd796e365dVirustotal results 0.00% 
2023-06-13bZhWTYSzoTuiz.jsjs 34eaf742d49a5ef0b40e705fde1a2780ef70ce88d0d35d473112002dbb75322eVirustotal results 0.00%Quakbot
2023-06-132vYVj3ZH8oC2z.jsjs 8b9e0246b8885c915a4b0f7e1a2b4dc12814de55b4bc2295f5942b9607275fedVirustotal results 0.00% 
2023-06-13StjLYl0ZV4wgpy.jsjs bc7f8a0c0173cdb7fe20372bc4ed888006702d7882dd8a12d619afd70fbf1024n/aQuakbot
2023-06-13FRE40Rke3Y3y.jsjs d128c1ca12beaff1951aeb80aff1059daa87442e39a5c2bc1674441a7561b7f1n/a Quakbot