URLhaus Database

You are currently viewing the URLhaus database entry for https://clinicamedicacma.com.br/dro/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659378
URL: https://clinicamedicacma.com.br/dro/
URL Status:Offline
Host: clinicamedicacma.com.br
Date added:2023-06-13 17:52:24 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:55 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 22 hours, 8 minutes Poor (down since 2023-06-15 16:02:04 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BD570_Jun_15.zipzip 85217c4410969151c0ebd4145b766f40d1afe1530bd2401babc4472e382fb4faVirustotal results 6.45% Quakbot
2023-06-15document_CE469_Jun_15.zipzip 7a894f1970bd1689a2019b68767fcafe284373a76b1c109888d2671cf7d1a7edn/a Quakbot
2023-06-15document_BA598_Jun_15.zipzip 9406c0ca1337e0b9d56475d9d814e969e755ec313997d5893daf2106ac717ee1n/a 
2023-06-15AXUn9iR5LU7M1K.jsjs 4c87b161e975c48acc915fa8e0c1a5e11eec00d2ac9708dc44d77130ec910b00n/a Quakbot
2023-06-158pLVeIClgSt0ys.jsjs 7bcb66a8f3fcf73fd41a201d2cb769adeee29f4988274c01805b58972495d9d8n/a 
2023-06-15WNUXXIzuUv14R.jsjs 231f38cb88c8415fa94d1bd17242cdfe3900ca9ea834e1351c5d9153fecf811en/a Quakbot
2023-06-15CBoExdNRD3daJ.jsjs 1fd9f8bad73ab4aaa6dd0e604731f19441af3009ce97595a27a8a4aac354d760Virustotal results 8.47% Quakbot
2023-06-15Hnf6zAMLUZH2o.jsjs 82cfa160e6630239ebe1cc418631760d9976501d3bfb6051555311326d82ff18Virustotal results 0.00% Quakbot
2023-06-14ESzErZnyaVHa.jsjs 0f4fbf3274a01308338549613f10d55e9fb0aa695e8e066961d75e232df75ba7n/a Quakbot
2023-06-14LqkYmXqfSxyT.jsjs 7eff6317bd536274db3bfff479a6e908c1f81711af4d8c4ce04cd4b2387d13b2n/a Quakbot
2023-06-14JiIrgGWdBtlnG.jsjs 80d8a350eea506a55c05d2d9623051310ffea615d600c5fd0857a5b6b93513f5Virustotal results 0.00% 
2023-06-14MPUfi4TvjCkezw.jsjs b8038efcc7569f22a53002e829b8bc3a42dfe16dfd7ebb38c9ba168154ce2e1cVirustotal results 0.00% Quakbot
2023-06-14KZDu4HpzfY60a.jsjs 0b45bec0aa6e9d9969b6be347fac28fbfeac0102e552da0dc28e362f32c60f81Virustotal results 1.69% Quakbot
2023-06-14NIzZQr9XTtZVzI.jsjs c3d5d8ed3d43929667664123681968458f8e57ed8eb6c2c1592b2a09db0a7575Virustotal results 15.25% Quakbot
2023-06-14ZTBmezckK5Cp9.jsjs 77ee59f5de41fe253695de13801bf06c13dedc1897fa9fb15b5b6e0635c2455bVirustotal results 0.00% Quakbot
2023-06-14JhRdCoW2hGx5.jsjs 31250587f0bc18aad546f183b227908c80f3f8eb532618bdc9566b658a2be857Virustotal results 15.25% Quakbot
2023-06-14BxIqeiILZAnwhJ.jsjs ef81c6dabbca977072412b84e9fc55918ae8dd802ad2919d06133a39faf54fa3Virustotal results 0.00% 
2023-06-14KMlAyEwAhXZaM.jsjs 57c6e46915487292316b14b5703105f8dcd0d12e72510826abc8146f94789650Virustotal results 0.00% 
2023-06-14EE0XR2vPjygZ.jsjs 62e19a10016116eeda057ea57be07429e37d899d590237a0066002722f46bdc8Virustotal results 15.25% Quakbot
2023-06-14ZBnCgr0TgNBx9Z.jsjs 820bcaca6680e62df21937deb4532788dab7cee80bf3aa6695b169dc4ba41c71Virustotal results 1.69% Quakbot
2023-06-14SpPlHsZSO7GIeM.jsjs 23da164d706040d0cb704af26f9d84ef128d4c81fb22c9613154a5b845d477fdn/a Quakbot
2023-06-14UaRhpQd5DFODnX.jsjs b4e17241304cddc6bb0ccb0fdcad130a8c50c007d3850e39ce6c8d3f24865201Virustotal results 0.00%Quakbot
2023-06-132G5oZwVmC4vBJa.jsjs 50ecc004c17dfdf0cfd97c571e3f51c8e79e0502a93203a3bd86ac7ec51611f6Virustotal results 0.00% Quakbot
2023-06-13P4rBt0Bi7g84Wm.jsjs 0e2c3e6d62c9a7aa6af1ebe5f83d3fb9a5bfdbfb39fb17bbff0040137907ea2dn/aQuakbot
2023-06-13rtAadZ3Rq8H0OE.jsjs 52029a2f5051ca1ea16887ce8a453cf92970b3b1b828ef9c388b4e4aed6649bfn/a Quakbot
2023-06-13Ykx2d2RHL3Ckeb.jsjs 518bd813c077206e330fe7abf815319c60311bee93ab5a5ed776f1fefa9ff8d1n/a Quakbot
2023-06-13HoaONDTf10XZz.jsjs 99ce6d054dbab9f27faccd5f658d5dce6fa331a12f076e2153c851f49a44045an/a Quakbot