URLhaus Database

You are currently viewing the URLhaus database entry for https://paroquiacampelos.pt/nu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659442
URL: https://paroquiacampelos.pt/nu/
URL Status:Offline
Host: paroquiacampelos.pt
Date added:2023-06-13 17:52:45 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:55:05 UTC to abuse{at}register[dot]it)
Takedown time:1 day, 21 hours, 57 minutes Poor (down since 2023-06-15 15:52:33 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AB753_Jun_15.zipzip 7c392963138a7811d69244c22a9f42ac4322898e12047bdca69049be286a4bc7Virustotal results 7.41% Quakbot
2023-06-15document_BC132_Jun_15.zipzip dc312426da8604056e90811a7039ca8ec070d805a9ddb630e3901c4d6fca8032n/a Quakbot
2023-06-15rO5gN0Dim6Wzq.jsjs 14e007c5828b6fb4aafa65b441284a1c97374da67b5f5debf944a38a35b611ben/a 
2023-06-15O2D3LAOIxxxo7.jsjs ca5094f3caa21967f400d8492ac20242987429d31b18d47711bdf60ae1b30477n/a Quakbot
2023-06-15oSiTotaufkPe3.jsjs cda5d469469b2eabc0019abf0af3a6b11df31d048f05c1a1cd4135ef41e2c2e3n/a Quakbot
2023-06-154jWFmFFBJ9Nz5.jsjs adbd39a068fed7567f68e6fe741f65352efc5d631ccc48c4f4c1f9ebb01dff4bVirustotal results 3.39% Quakbot
2023-06-14nTiseheA7jOcI.jsjs 1103ab63a80bf6fb978a57e942cccf0dcf00a0240ca9e03a8337ef6d358ed5ben/a Quakbot
2023-06-14docu_AE961_Jun_14.zipzip 4f17c73b4256580ef3946d9582e394e7b00b5c1d3f2309847c649e5c90dbc20bn/a 
2023-06-14docu_ED627_Jun_14.zipzip a8fa341a4092c92e4dc493a747766e8726c2c92d4c7a894a7044040df441d369n/a Quakbot
2023-06-14d5Xxij6y76ZyF.jsjs 3280edf0bba5b62b32a203f2786dbca78088ee6ee08de398badba5c0dbcddc2bVirustotal results 0.00%Quakbot
2023-06-14RDaVUOTJvy9B.jsjs ceea44b69d9990b83357e10cc5b3024dd746579c1a9b43c63b514b713532f6e7Virustotal results 15.25% Quakbot
2023-06-14E9Z5x7bxaF4eZz.jsjs 8b9f00478811eaed21f3759ccae2433a5fa7167dd35dce760974ef441d464962Virustotal results 0.00% Quakbot
2023-06-14L9zLS3kG2hRVF9.jsjs a65d05999b9e84c699e8cce7c926554e78a0d71daa1acb64ed8fe4e344a67f40Virustotal results 17.24% Quakbot
2023-06-14EvcG4ShDrxie.jsjs c560caa45b825d01ec9bf2dd4eaecbe7e34c80301c4c5ce8bdfacade0f7e3e4fVirustotal results 0.00% Quakbot
2023-06-14qjyYassKw6Qn.jsjs e552985ff266e1634976236fad4ea1b67d242a95399d255c9b984d18e93fb934Virustotal results 0.00% Quakbot
2023-06-14NH0zZWWyGNkrD.jsjs 1b7189eb51cbca5cbf5c1a5baab3a5321c19e823e689282afa1c1abf398c4f73Virustotal results 15.25% Quakbot
2023-06-146xZKbBFcl5elIP.jsjs 12aa30c168e0bfb3f09cd7bcd823186ae8f4a1bafe7f97e3a0fd6b925433587eVirustotal results 1.69% Quakbot
2023-06-14XwNSi6Zgv6YMZN.jsjs 5e216123a0bb3c8af5d41e74ee1abcb2b437d6a842564892d1dc82df58945e62Virustotal results 17.24% Quakbot
2023-06-14AFJ5ZiVbTl8R4.jsjs b0c70e0ff93c798e12fda4250c14f7b6ba871df13eb40e2edebf33d32f5a0187Virustotal results 0.00% 
2023-06-13CJx656j9deITW.jsjs 6f15874486bd4953cb54fab2a06baf0c353af8f01cb0538c976563ab8cfb2b2en/a Quakbot
2023-06-13FwWzvjxiHICUV.jsjs 1c3df14b4ca34676e0e79da065079cb8ba3e14b36940d95feb65f51be77b3056Virustotal results 0.00% 
2023-06-13freys90fXXS5f.jsjs 466dea06686c065a5ac52c98c45beb0fcfde21d035d466604b37245d7746432en/aQuakbot
2023-06-13rnm8UcCo1IhpB.jsjs 69b80b67a6c963fa6d00d4fe7ba7d280cf4c16753fca11691d917a50bffe9ad6n/a Quakbot
2023-06-13aYQa9wQyAZZ1.jsjs bc64caf34f92e2e6f063ced2c6d9e82ecfab18b7aeee5767de6094fd960d23aan/a Quakbot
2023-06-13Loblu51Hfvc72.jsjs 6d8348cec331ee7d652dec435f1d5a3a513697040b79e3b86f268cebd42cd525n/a Quakbot