URLhaus Database

You are currently viewing the URLhaus database entry for https://conectaip.com.br/ee/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659978
URL: https://conectaip.com.br/ee/
URL Status:Offline
Host: conectaip.com.br
Date added:2023-06-14 09:02:10 UTC
Last online:2023-06-15 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:03:24 UTC to hostmaster{at}registro[dot]br)
Takedown time:17 hours, 50 minutes Good (down since 2023-06-15 02:53:38 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-1414Ub9OVdg0JDuz.jsjs b4ee324ba228514323709a8d09fbcdf5bc1250e33ca44c6fb99160a9971e2e12Virustotal results 0.00% Quakbot
2023-06-14IAhCKKQTtWBLs.jsjs 9db3d0bc1791cdc5b60750a1a38d467325124088fefcc1113a5db1c14dcb001fn/a Quakbot
2023-06-14636pcrsozGvh.jsjs 2ddef774dc4bfb6516396d8de580f0960d0f225e79077dbab7d317ad7b67eadaVirustotal results 0.00% Quakbot
2023-06-14QhsY7LOvvegPF.jsjs 7273b75e139f3dd30809a4e9c1abeec754ee24b0a7f1ccc2333727449802fb81Virustotal results 3.39%Quakbot
2023-06-14S0KAnumfvmD5.jsjs 3640f0af77e63c02085b4ae6b22c7e4977ec33ca0d9c67e15d5bb7f5d9b96d3aVirustotal results 1.72% Quakbot