URLhaus Database

You are currently viewing the URLhaus database entry for https://tuluk.arq.br/ptu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659359
URL: https://tuluk.arq.br/ptu/
URL Status:Offline
Host: tuluk.arq.br
Date added:2023-06-13 17:52:16 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:36 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 1 minutes Poor (down since 2023-06-15 16:55:13 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CB358_Jun_15.zipzip c1135e6a9ae9237a05ae2af99d3d716ff866182f8f380385fcadd31816b1f5a3Virustotal results 6.45% Quakbot
2023-06-15document_ED859_Jun_15.zipzip 106cad7af088a4e52d6745b0920dae93590aedce42ca7eb07d9f60abd8b23f62Virustotal results 6.45% Quakbot
2023-06-15document_CA532_Jun_15.zipzip 9519d3c70bad04d639873224dfecb2099ad28cf4ca3af0c34f948aa852f42de0n/a Quakbot
2023-06-15iRWYt0MUBufqX.jsjs 9ec20cb2e9b4f2752e8b7a45faf7bccf2c5ad39706b30bf2c3438039b6630ab4n/a Quakbot
2023-06-15HWXd0o01XB74.jsjs dbb099422bc8c329ab699d86e04649ab7855111126f2aee894307edca92dff58Virustotal results 15.25% 
2023-06-15TCZTGlpL6Qb2C.jsjs 04c5f38b95b2f219f6ad6e015c56129f2245525e3ab29783cee7b3e5ed7eb198Virustotal results 16.95% 
2023-06-15GE0wtfPigPLhH.jsjs bca7676de4d6ea8a522cbffdf51bd46782c91761d1b3bf670544ffc90270c058n/a Quakbot
2023-06-155skjmCwXa01htn.jsjs d144eb689651e36f019795f3149f2cace152ad96b91baf03b75dfeb799c54c84Virustotal results 0.00% Quakbot
2023-06-14NOpkrGcAz60WPT.jsjs f7a3c37c75452508ee937b87050a1fb4e64c4d3d5a8631a2635ffdc1e4312daen/a Quakbot
2023-06-14wYRHLyTrIwGtE.jsjs 95a953bf6f61d864c7a1c985d7c02f011b410259e74874164c55638ad344ae99n/a Quakbot
2023-06-14mpM4gHEwPkCz.jsjs a1cc109e0f24ec62059986c929a67da7fb8f555d3a1b7c406ac3ba7a958f3fbcn/a Quakbot
2023-06-14docu_BA301_Jun_14.zipzip 197c2db0857bc2cd2b24856ea3966173990489709337aa4a3bce6ce17e9e9b22n/a Quakbot
2023-06-14Dh8mjil3JTWzPh.jsjs 472ff47b3a901046d5f6772ee705bfed57f93779d1630959afd8ae08c85f977cVirustotal results 0.00% Quakbot
2023-06-14plNITUAExbTg.jsjs 70bcc77132ab2141c18165d1b8238199d381d58e4eb5096871d34079688ad75cVirustotal results 0.00% Quakbot
2023-06-14DcMhV62519tEm.jsjs 3f55ba89edc7119571a5e449432a86e46db42b02a85961e11a6e63b91514cc36Virustotal results 1.69% Quakbot
2023-06-14Y6THE4OcEBtf.jsjs cf8bc1bbbf24b2b6024ac626ad92ac3a48f55307d7ac30029242f0c0cb1fa018Virustotal results 1.69%Quakbot
2023-06-14WJGd01YkiHTz.jsjs 5eddb9f95ecddff8a626830f3439a863a744ca2be7539c838ad2ebfc2813c402Virustotal results 1.69% Quakbot
2023-06-14IhcAwi6yaFyuk.jsjs 199f8075ae65ab51a377fc39b0009f4d371d893da6d4e66bbb2cbec5219d05ceVirustotal results 0.00% Quakbot
2023-06-14hTKT9F5vsyw7Ho.jsjs ef19a28a31c03a8144ee523ee5bbd0b35e41fc48a288df54a87e41b3e9647cb4Virustotal results 0.00% Quakbot
2023-06-14f0ADIPqU2CuN.jsjs 56b609a268af95d2d7641eaf52367a0438cded8eb26f98a02bee6aa399eb81d8Virustotal results 0.00% Quakbot
2023-06-14XGxip1yVle4eR.jsjs 5d08881aa3a04ff8fe738c44d7b2cccd96603a5c02629ce83036c6280774e64dn/aQuakbot
2023-06-14El1zlPYNMGX0SE.jsjs 7a686129f8d2aa3974975aa9c0c053956a35a0e41ef1a0ebc8c57f7c19a92caeVirustotal results 0.00% Quakbot
2023-06-13VVeUNhHwbH3d.jsjs 5dcaf44cb684b3f97499442be32f7260097f59b2b4d35d1c0902cc43c45f3f90Virustotal results 0.00% 
2023-06-13sDTJ4y23w2iN.jsjs 429f40203cb0309daa8ae8225006da50beaf1618be71766fade353cd796e365dn/a 
2023-06-13VW2EYAO9FPBO0r.jsjs 53c1fa6e950d5688bb7ecd26f397579a37fcfb28d12869a0b7f7c4899a9d6cc8Virustotal results 0.00%Quakbot
2023-06-137DBQUgPnI3LD.jsjs b991216bb3755a58e41ad9043574ee4d6f61418801a3fd09cd3c191a1de7b92an/a Quakbot
2023-06-13FrUgdIvvoR28tT.jsjs 82b17d96fcde5c20b335e5ee193a154e9c5894908088bc650b124f10bb1ad59bn/a