URLhaus Database

You are currently viewing the URLhaus database entry for https://restodoporto.com.br/ndil/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659400
URL: https://restodoporto.com.br/ndil/
URL Status:Offline
Host: restodoporto.com.br
Date added:2023-06-13 17:52:30 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:54:21 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 22 hours, 17 minutes Poor (down since 2023-06-15 16:11:21 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BF248_Jun_15.zipzip f6f5738c9d07bf3f7eb04cfca60bcac0c019738635131b8a1e4105d053ea2fb9Virustotal results 6.45% Quakbot
2023-06-15document_FE651_Jun_15.zipzip 442a788b25ab5bf166940345f08f620260c35f26ae52579147f6af2f063fe266n/a Quakbot
2023-06-15PORud2qg5qQh2.jsjs 356a629e04eecc0cf77c3a249ad2d257195d824203414c3923960c0de753dfe8Virustotal results 15.25% Quakbot
2023-06-15adudlpXH9BqOYE.jsjs 106a06ba68fab33718d88c828557ff8df114a01db94f0a854915b3773976fe9fn/a Quakbot
2023-06-15ljGrDxuverun.jsjs 1d06b1738ed11335dc388594fee6551422e327aa4f9cc22b39c56dfd9de45398n/a Quakbot
2023-06-15K7wpjlMTKCPNoY.jsjs 1afe7cc14d470b62fbf984decf3a3528e68d0ac84f9a4a3e62333a0ee63a132cVirustotal results 0.00% Quakbot
2023-06-15wmsBOhzhygvUw.jsjs b78b54f956b95a726a95ec2bdfb3e99a516589b557df5dcc2dc5379484114d54Virustotal results 16.95% Quakbot
2023-06-14wYlhhzElbSSpy.jsjs 54028e894dd48268a588562e0864a85970ca56788af10ba2474af3ec3a3fec22n/a Quakbot
2023-06-14PCeuNevQXAjn.jsjs 553c3c756266c1c73bfb70a56a012a3dda9ac8e7ed99d513e89578d1af084bd6Virustotal results 0.00% Quakbot
2023-06-14docu_FA504_Jun_14.zipzip 399bef95a290ece265c8251f4c1cba96457fec13734d09bba3207aa862be54aen/a Quakbot
2023-06-14docu_BA301_Jun_14.zipzip 197c2db0857bc2cd2b24856ea3966173990489709337aa4a3bce6ce17e9e9b22n/a Quakbot
2023-06-14o8ZhTR2TMTtVBu.jsjs a4723a14b0f4cb97c6c12e88d9350a036a568b5b9edd60ab1f21ace5c41d96e0Virustotal results 15.25% Quakbot
2023-06-142wy2Jk7KLOfz.jsjs 055dc4c4ee27b80abbee11617724554d34acbb425aceae1c31083118dbaff67dVirustotal results 1.69% Quakbot
2023-06-14El1zlPYNMGX0SE.jsjs 7a686129f8d2aa3974975aa9c0c053956a35a0e41ef1a0ebc8c57f7c19a92caeVirustotal results 0.00% Quakbot
2023-06-14ZOTRrwJXjmtfwZ.jsjs 5cd2f0d80b5f451a5aff75feb9897bbd7ab37921cac6ba7b59bdf50ffff64e52Virustotal results 1.69% Quakbot
2023-06-14Yea2QDFuLFAR.jsjs 67076bab342d29b913071be1cd29b60d1800fda7c0f4379f8f5adfb4e3b6f0ceVirustotal results 16.95%Quakbot
2023-06-14ehSco8ueBzmRMV.jsjs d663d679bcae514fe5d4491ad3b4e9a365452cc2b786b59a66c8ff9f72d7b239Virustotal results 0.00%Quakbot
2023-06-140F4lwqe3vaYa.jsjs af9a41141e77ece9fc895c1cf2c7e244f1f0f605cc25a62ddbc77fd0751cf22bVirustotal results 0.00% Quakbot
2023-06-14kNHvtGkegAH8pE.jsjs b3211a16069b7928e1bd457442e5816b09d29ed9baa96db0c8feea2e00069609Virustotal results 0.00%Quakbot
2023-06-14O4kzGjp5130Fp.jsjs 325e486140498c768d75e86b2139832ae5fb99960c3a5e5ab1aef3940146850aVirustotal results 0.00%Quakbot
2023-06-148OuHtQacocDdgm.jsjs 0ba21385c79af7af3a4a4cf757a2d3ff6dc0d9873689930d58f713288f671b9eVirustotal results 0.00% 
2023-06-14HUevUTxOkIc1U.jsjs f402b8848c5cdc6de1de79c42976ccf1b2e2b4f301d942d3c9eae9c63bcf5374Virustotal results 0.00% Quakbot
2023-06-13U5eMkRL6CbFETE.jsjs 4573e411b70a42868e2b1d62ebddb99005c241abae8eb6652d2e1d1e3b815681Virustotal results 0.00% Quakbot
2023-06-13GPNvhk4Db3CeKm.jsjs 7a3dd2afe479c3455a453cf42e01bf511c3eb31d29866a382a3e5257912dfeecVirustotal results 0.00% Quakbot
2023-06-13UT1hcionG3ul4U.jsjs 39812c0ab253e75f4835c0da4cb08db82f3c7954ccfc3d9a989944c1ae295f8eVirustotal results 15.25% Quakbot
2023-06-13aMe9iCMXBtlJlZ.jsjs 6d5f22677d533a9fc11c5c01590b32eb2974e96e0da226717203bca23433ba8bVirustotal results 15.25% Quakbot
2023-06-13HiYLsDjAycE7eG.jsjs e9463170b553a9a93634d494cb40fa7cb1262eadac1d486ecee9acbee098cab6n/a Quakbot