URLhaus Database

You are currently viewing the URLhaus database entry for https://odairsilvasp.com.br/elt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659370
URL: https://odairsilvasp.com.br/elt/
URL Status:Offline
Host: odairsilvasp.com.br
Date added:2023-06-13 17:52:20 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:47 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 22 hours, 15 minutes Poor (down since 2023-06-15 16:09:43 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BE201_Jun_15.zipzip 3a29fda2356a1b67b775ef538667889559651a987e020ec5371550d365486798Virustotal results 6.45% 
2023-06-15document_AD278_Jun_15.zipzip a68301645409a864428d308f5f5924cc06f9997915cb057483429613f091409an/a Quakbot
2023-06-15document_CE593_Jun_15.zipzip 3c58954b24d8a766eefd1363923a92b78cb6cc39d4b320ed3e09a4cb7fa9bf2fn/a Quakbot
2023-06-154D9gkJ2QozGnc.jsjs 13f2413326f045966aa5d2fbe65a391fa955a807cdbe42ed65c652b4aa08000eVirustotal results 13.56% 
2023-06-15eumlL90o6HB1.jsjs d4c8ec56839c0315ab6a3aecd8061f522d49618c8c1709396b95dae13fadee8dn/a Quakbot
2023-06-15HaujPtdbmKjb.jsjs 5fd07e92ded318129e766c0a0500e3fec1f0775b7579316a786ca4989357b8a8Virustotal results 16.95% Quakbot
2023-06-15aoFXedMzbCR39.jsjs 9425428aa93ca666e5f9477a46519b5a116f78ba709b69e84024e87a61241a42Virustotal results 0.00% Quakbot
2023-06-15dmaro7yH61eyLx.jsjs 925201643d063bf17ff6f18dc4c7c9b00f7c470c4f8ad7b2cbe70ec2fed33678n/a Quakbot
2023-06-144tXj4KyUc9Ln9n.jsjs 3b568e89fab409e0754948c1987378138d0dd217fa3be577e3ea103d11bb05f7n/a Quakbot
2023-06-143faykqOiy87L2m.jsjs 74fc21c059a81b78b0179a6957f8bf33d670e6ae304ffe51e61654245fcda8den/a Quakbot
2023-06-14docu_DF631_Jun_14.zipzip dfe99e49909839abaa99142b09b1e8eaf4d5ceb9e5880e75b045fc2c805c4f7en/aQuakbot
2023-06-14z16q1lhMharXwY.jsjs a04d8254c4cc0defe1bc3f7b5ab19b1463c852fe259a73db104b293817f788ffVirustotal results 16.95% Quakbot
2023-06-14FxMjLMJKKx2hW.jsjs f430f567fd803a9912cf105f9a5a9cc2864a52bd7089bdd191e2a8c5fca206ddVirustotal results 0.00% Quakbot
2023-06-146wJH0jm4j23t7.jsjs bc0be1ecb44384e84b69589fb5f91bad677cab2ad17f1d769dd64054af541a21Virustotal results 0.00% Quakbot
2023-06-14g7oMUPzhllj4.jsjs d835fbf3654c7b0a2fe8de58cf8545880abcfbe6997bda462ac909881963238bVirustotal results 1.69% Quakbot
2023-06-14YXZBzyvUHeTN.jsjs ad95395315d5caee130c970112020092bef82a19e7f1c607a5c81a2152a0bf44Virustotal results 16.67% Quakbot
2023-06-14PiYthxRecu4egq.jsjs c3242db5ceeb2398bb421cda160aacbce70b1a1673ebb2d643963d6d677dec6eVirustotal results 0.00% Quakbot
2023-06-14oHltis5AFif45.jsjs fef05fedd338a31b2f0c5bfc73323aa703677c68487cccefeff98c72d5178edbVirustotal results 0.00% Quakbot
2023-06-14ATEWDowRMklH.jsjs eaf14fd91a404ec47a95c6b3175afc8d53378392207be3f339b5df30e3f47731Virustotal results 16.95% Quakbot
2023-06-144GWT3o4psztJ.jsjs 940f269d5b9a5c931664c4c5c57f55d309fa906d549202f8e793948ba8826c15Virustotal results 1.69% Quakbot
2023-06-146xZKbBFcl5elIP.jsjs 12aa30c168e0bfb3f09cd7bcd823186ae8f4a1bafe7f97e3a0fd6b925433587eVirustotal results 1.69% Quakbot
2023-06-139XTC80O7MsoG.jsjs 56b1c95adc775a79029a8607e6d8bd87e286367a38ef9a2ac09edc306b3c14aeVirustotal results 0.00% Quakbot
2023-06-13FftiCxVfpFmX.jsjs 9f9895cbe88811eb4a244c7ee0b6d3868136a1e1662bdb0202ebdb5930980609Virustotal results 0.00% Quakbot
2023-06-13QBS1j3HXRwkf.jsjs 52d7a3eb1a87e1844d40bddb7c30f0a99000d0e5aa997c8e2b458821bc79f123n/aQuakbot
2023-06-13L3TVHKpg6yfhD.jsjs 7fb0d0d006fb2d1a05576482a1acdfdd21d674d14f989933f67a5d2f594c7b30Virustotal results 0.00% 
2023-06-13tVyIxBtasmID.jsjs 810fa023cdb19da4cf83092f3a429559fc8dbe01d15b3d476ec8be0822b3b4e7Virustotal results 0.00% 
2023-06-13E9Z5x7bxaF4eZz.jsjs 8b9f00478811eaed21f3759ccae2433a5fa7167dd35dce760974ef441d464962n/a Quakbot