URLhaus Database

You are currently viewing the URLhaus database entry for https://cosmetici.com.br/dni/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659455
URL: https://cosmetici.com.br/dni/
URL Status:Offline
Host: cosmetici.com.br
Date added:2023-06-13 17:52:48 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:55:21 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 22 hours, 4 minutes Poor (down since 2023-06-15 15:59:54 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_EC462_Jun_15.zipzip b1b29c105b7ca9414002ed608ee8aec804d756925a16877fc0d8a6d9b272a816n/a Quakbot
2023-06-15document_BE094_Jun_15.zipzip af17718a960ccfdac82b5b6b513307b88194ed78f2b6b476a89e783498c156e6n/a Quakbot
2023-06-15Y0ztSWaJlQOf3.jsjs 2b4d7a07c330ece34fc2fffdaa0fa147ad35d97221d9a1163dce4366dd4257e7Virustotal results 15.25% 
2023-06-15RCPvGbv76hvMjQ.jsjs d1e131e24dfc38ea0883c94ff86e7ede73c5db56257b802a33fa3c639b0e7e1eVirustotal results 20.34% Quakbot
2023-06-15Fn43xBpm6GlHeQ.jsjs 47a8edb0c660a7a8b630b9426c5ba7adaea358c97a6e7d70a41426e5c37d9353n/a Quakbot
2023-06-15R4JT0AqOa5pJL.jsjs eac27978ca24fec75ab281645b0f8e75e86f1b861742d6dabafd7ca86ca3700fVirustotal results 15.25% 
2023-06-15BeXh9flpLXZj.jsjs 1cc9b8ac64f4025144212c5262b32aa8e768e45c869f2d298de9ec726e89d1edVirustotal results 0.00% Quakbot
2023-06-14wzJUBM8uwj7o5.jsjs 4d21f1cc62ff981db834b29c4317388c7504e3724395c105640666bab48c094fVirustotal results 0.00% Quakbot
2023-06-14aMA7nmTHuZfp.jsjs 150361fa0e3890bde01a72818bb87a540e1aa9f31b13a18ad0beba518d3753a7n/a Quakbot
2023-06-14SQy8xBEpG62uXY.jsjs acefae9cf9ad1242d70a98450990bf561d7918326c9bf3d9519018f4799fd112Virustotal results 0.00% 
2023-06-145vWbvSDSs18Jl.jsjs 930344da054b37c5cc4ce764b1562976503b8062063ec52a0535b3d5a00ff583Virustotal results 0.00% 
2023-06-14Z1bIYGxQcas5RI.jsjs 1b47d55fe6a8cf401ea08c28473c2c24938b7148b8e0e6e2970f56b9281451ddVirustotal results 0.00% Quakbot
2023-06-14FftiCxVfpFmX.jsjs 9f9895cbe88811eb4a244c7ee0b6d3868136a1e1662bdb0202ebdb5930980609Virustotal results 0.00% Quakbot
2023-06-14LBnQr38Tvr6LYT.jsjs 570774e9bd1a8f8eae9a1943d1e3fc537ef304460db22a989261d9201d1d2206Virustotal results 15.25% Quakbot
2023-06-14tDSIPtjiHVjMI.jsjs c7b1f5bdba77ee38d49324f1e11eeafc16f5c6d58fb0f12be4290708730b5765Virustotal results 15.25% 
2023-06-14Md175YlLRr2i.jsjs c72f9d4985280477c1b57234ed6fdb9d760060d765c03db312c206ea35e8cb98Virustotal results 1.69% Quakbot
2023-06-14KZDu4HpzfY60a.jsjs 0b45bec0aa6e9d9969b6be347fac28fbfeac0102e552da0dc28e362f32c60f81n/a Quakbot
2023-06-14vJyTZhiwxOHCwl.jsjs 04d85875b74d2fb23177f6eee1a9c9ef79cdc7d0e0487718993dad7161d40868Virustotal results 15.79% Quakbot
2023-06-14UtyFjVGJJBGbZQ.jsjs e9ab96a64f988ef64c92226ff9c2411a3b4f055f673995e4e6e203c3c9ff3e24Virustotal results 0.00% Quakbot
2023-06-14tHtrJWsTSDWd.jsjs b536742f4c71b3e6ebd5f9c0bd7755c1b4ed815fbd0bcf3b8c1b9a8f5fa0e0d0Virustotal results 15.52% Quakbot
2023-06-14NWnsm6cFmfw4p.jsjs f4e6c505a295f068260e162b3702b38adb2506af13c64162cc2b517fc9919453Virustotal results 0.00% Quakbot
2023-06-13kyvmbiJE7M4M.jsjs c9f9c016085e20f6f3cc4ce1a2be8de531b3784c2aed172fd0f3c28b13206034n/aQuakbot
2023-06-13xLQyVdGMefULEU.jsjs 2a272653b56b77d03cd623abe943e7f0fe965b1a381184a2e6596be9eb9afdabn/a Quakbot
2023-06-13EE22XfspgzgfbF.jsjs 59eb669a757058561ea4c07b922431289017a7bce6a4f8a1fac76b85c30ece5fVirustotal results 0.00% Quakbot
2023-06-13tqHjbZdhAR1r7.jsjs 8fcec0e00b5c30b684c0b9968ffdc5c3fc156af7e2b742f3cb70342082909f3an/a Quakbot
2023-06-13MyHIhVUB0umV45.jsjs 702b05b838fa4bb7e62f8c97a3823c6d813ddc3b1a1b44e83225def58d0022fcn/a