URLhaus Database

You are currently viewing the URLhaus database entry for https://fortrealrei.ng/oe/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659987
URL: https://fortrealrei.ng/oe/
URL Status:Offline
Host: fortrealrei.ng
Date added:2023-06-14 09:02:12 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:03:35 UTC to abuse{at}liquidweb[dot]com)
Takedown time:1 day, 7 hours, 42 minutes Poor (down since 2023-06-15 16:45:47 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CA480_Jun_15.zipzip eedef75c9e4577fe16cc82ae8c668aa8152d83b893dbf941504f8754317e3455Virustotal results 6.45% Quakbot
2023-06-15document_FB382_Jun_15.zipzip b26df4dbcb0f93c82f114ba3aadc52575f41bf159abdbe2753804de69d6f1640Virustotal results 6.45% Quakbot
2023-06-15document_AC617_Jun_15.zipzip 21e237be89dfbef741afdbd68e3068d31b63d23de6b076750a455b5b8470c346n/a Quakbot
2023-06-15U5wnJgBjGDqJKh.jsjs e678892d71a60d96ffe75a0434531589e3fd317ff116eb8bec64bd0f9b796740n/a Quakbot
2023-06-15KHrPbXdCMiWU.jsjs adcda4de90068192f647c4ffa8e3e9a7b5423339da77d3dcad6fb60676787c05Virustotal results 18.64% Quakbot
2023-06-15SxT5CLilvDWJ.jsjs 93f9f668def973225fbcc977362fa7704d84b698b48d87c2294221092036b3a9n/a 
2023-06-15RjJBywTgNehvN.jsjs d8668e2c2aed9a169c742af03b61b5c265d3a9314e5540aba018182ab34aa3a3Virustotal results 0.00% Quakbot
2023-06-14hElNbSfdQlfF.jsjs 592b21e6f85359faaacef7aab8a33811f98fb928f3f4c818df7f6e4d451ad14dn/a Quakbot
2023-06-14W4rFrbax5Thpd.jsjs 1f9aec5a67f9712f6a741ae65d92ee5a5958f8594195c27d190b48108fde8c87n/a Quakbot
2023-06-14docu_BF543_Jun_14.zipzip c673bfcb47ede45a743fd4f7a77f4191994558953aa9456806cb2fd6281a9031n/a Quakbot
2023-06-14V4W7Hf5zwlDL17.jsjs 2a406608a0ffaba2656cf5879e23dfbe00108787515fb0cf28a1f28ba8b06c94Virustotal results 1.69%Quakbot
2023-06-14SyluCEzqroQN.jsjs 3f65fb92383f4ba551003b030280c3b28855834ecd6b3228a73ef2b96616f6e3Virustotal results 0.00% Quakbot