URLhaus Database

You are currently viewing the URLhaus database entry for https://morroazul.com.br/aeis/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659352
URL: https://morroazul.com.br/aeis/
URL Status:Offline
Host: morroazul.com.br
Date added:2023-06-13 17:52:15 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:29 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 22 hours, 31 minutes Poor (down since 2023-06-15 16:25:21 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_DC329_Jun_15.zipzip c0536ef60b956978c7e54220ec8dfb12d292088862715db7d118786c9b7eeae4n/a Quakbot
2023-06-15document_CA153_Jun_15.zipzip 6b433e6368ba9fd66e6bd85c0025bd509fe2a93be9b98054bbe3a44180c41982n/a Quakbot
2023-06-15document_AC067_Jun_15.zipzip 27d27aea08ba1f849088409121fff47540aa6424ee5a9a5f38aa13d721b56710n/a Quakbot
2023-06-15nbHKRhcvc5KCI8.jsjs 5cdf7ea225d67a7639e6bae77e2a8e96850aa4229fd2e2db1195eca14ddbf32fn/a 
2023-06-15H8yU5r9CRolo.jsjs 9dfa556f1c7ff896c79a4c77153087a5fa263f11176495218af3f8ee8385aa05n/a Quakbot
2023-06-15IqJEPdFqsT269.jsjs 33dda8d7f3dc7abde925beb856e93c8d4570200e9bd76c4c688760683561d498Virustotal results 0.00% Quakbot
2023-06-15oiVXTJJxwOZGx.jsjs f7c453fb01b6ea20e8f3fc65bca3e6ccfbac00df127862a0b12400a25aba0987n/a Quakbot
2023-06-15jSKA5IhX3a2NID.jsjs 51630acfe12b73c4394b0e42e4a0b77a70fb178ff6288abd40cfbed7c473b97bVirustotal results 3.39% 
2023-06-14EmkFCp4EcXOj5.jsjs e929147b40a3c9bc6918edb1fe41453173adfaf92afdc18a0b3391e1414426aeVirustotal results 0.00% 
2023-06-14docu_DF172_Jun_14.zipzip b50dcde191da6147ec540e6999d5763a5873016dcd157fca26c3e9b61d37175fn/a Quakbot
2023-06-14docu_BA301_Jun_14.zipzip 197c2db0857bc2cd2b24856ea3966173990489709337aa4a3bce6ce17e9e9b22n/a Quakbot
2023-06-14ogbh8cDzs8FAb.jsjs 82d7fc23e0eb1d8f7ef83f5ddd41c982584b037116c2fb7e5fde41e756dadd24Virustotal results 17.31% Quakbot
2023-06-14HiYLsDjAycE7eG.jsjs e9463170b553a9a93634d494cb40fa7cb1262eadac1d486ecee9acbee098cab6Virustotal results 0.00% Quakbot
2023-06-14L1KhE2GwXpq2u1.jsjs 8b7ad482b2d4ae6336df9e63c13365e00e549e430b9a843d8a4e392a43a4d828Virustotal results 0.00% Quakbot
2023-06-14uChIeNTwmStIU.jsjs 0fd860961e1295b2e739caf4d4d6ca29eac0aba3f9ea84bc16dcbd96aee06fcdVirustotal results 15.25% Quakbot
2023-06-148uciwUJVhSAwIT.jsjs 045d32ff53f0c9151824d2dd6179dae546a81d95f3b862f9244a4c2f8b91e9e1Virustotal results 0.00% Quakbot
2023-06-14kQSkj5jcc83xWU.jsjs 964c22440234b645517e6252c5c09c6b4577df7416335aaf23f14eaf29f6d859Virustotal results 15.25% Quakbot
2023-06-14fD5Au6bGTvVCE.jsjs 0787387747384f631c0a746905175f19f71d462cfb3cf432d69cf92ff90953e3Virustotal results 0.00%Quakbot
2023-06-14vmP9rF5lrFzgZ.jsjs 0ae818b3cb8248d77466d4dccd518194094a6a50ccb0cacc0d002a612d0b9822Virustotal results 1.69% Quakbot
2023-06-14NWnsm6cFmfw4p.jsjs f4e6c505a295f068260e162b3702b38adb2506af13c64162cc2b517fc9919453Virustotal results 0.00% Quakbot
2023-06-14beQYlwdlmS0RsQ.jsjs 8913f51f576f3301a53cba804462f22c5a965e87e1acf37b23076fe661524998n/aQuakbot
2023-06-14GoFdaPyHh8QS.jsjs 302e7520d63d0aee99b626125c45533429d5cae1d0dc0b99ee16ebcd23a74f7eVirustotal results 0.00% Quakbot
2023-06-13xZJkf60MbDEsz4.jsjs 97b28de69acb52542ece68cf3c90c7c729661bc3154710912e0bc38f95df4c40Virustotal results 0.00% Quakbot
2023-06-13x3Kb4Xhdgc9h.jsjs 6dc6aca3cc4c22b24664c82e847e49311fe3d52b1d0ce82b4b25e7aa876d85f1n/a Quakbot
2023-06-13iZmSp3NBy3iNx.jsjs fed038e6d1a61372051fb708aaaf8ba258672cb324f3a1ef1e790245414fedb8n/a
2023-06-13P1FfUyVp30Eo.jsjs 0e8c06b0ceceecca29b95c14087a277ca66d8e0af6e49dcba8f588de5b98ae11n/aQuakbot
2023-06-13EGlKdomTlEaOGK.jsjs c25ecf652174f94ac18bba8177d5d8322fb31d649edabc523b505e815cc47376n/a Quakbot