URLhaus Database

You are currently viewing the URLhaus database entry for https://forms.cac.edu.au/ind/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659989
URL: https://forms.cac.edu.au/ind/
URL Status:Offline
Host: forms.cac.edu.au
Date added:2023-06-14 09:02:12 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:03:38 UTC to noc{at}a2hosting[dot]com)
Takedown time:1 day, 6 hours, 50 minutes Poor (down since 2023-06-15 15:53:54 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_EC512_Jun_15.zipzip eda00fa7b574a13d3cc935a197abbd0dcea6ac948e1b5c7608c324c3ffe4e5ceVirustotal results 6.45% 
2023-06-15document_AC943_Jun_15.zipzip 4310a5dbea366f3be5fa1c733056da6ac20f51a00c7db5ba5bb6453cac346a91n/a Quakbot
2023-06-15document_CA751_Jun_15.zipzip 0d89de890c71256b529aa92d2264126c1be727db7c5cfdb50235e06e09f0e404n/a Quakbot
2023-06-15LEWDqNsjbFKbp.jsjs 36b0f29a4c23445b92edf24eda3e481b8dcca5ac883c378752cc0586d60c7e7fVirustotal results 15.25% Quakbot
2023-06-15YkJcdFdNjoGO91.jsjs b6f2f70d5f7d8822c994cbdd69ae14546f24e314e74198a91d995fc4cc80d52dn/a Quakbot
2023-06-15bJ8gryLwEUfVq.jsjs 33b2fcb45797ee4f13c6b96c239938c82bc397219f3c0ecc4c5394ba163e2170Virustotal results 18.64% Quakbot
2023-06-15HDBvYQTUDhf97.jsjs c3c0943f728cc5c8ca3dd40711519255fbe295cb0b04ba6ce2e35502f6827c3dVirustotal results 14.04% Quakbot
2023-06-158YmZMK6urVNM.jsjs cbf915b3b20e70f979d9947a3759a8ec3a1a6e8cd4a4bab84a5a693b0df409edn/a Quakbot
2023-06-14zlSAzmNQcJbvc3.jsjs 722069c76637bbc708ec7ffcd3aa88ac69e6b08830910d34ff09ad327d5c3bb0n/a Quakbot
2023-06-14docu_FA426_Jun_14.zipzip 30c0a2135630654946b03acac59e7a62ab572aae0c0b16ef35eb853261b19bf7n/a Quakbot
2023-06-14YtLn6Ctai99v.jsjs e83b6b0ead3287fd0bf7919e1d5bff3813358bd73e9b5748dbb7f0007f1fb04fVirustotal results 0.00% Quakbot
2023-06-14DOwnePBYmjpf.jsjs d1d86bc8c4b7b5b439b81526da3587affca593de26bc275b93a7ead4976ef1d1Virustotal results 1.69% Quakbot
2023-06-14StjLYl0ZV4wgpy.jsjs bc7f8a0c0173cdb7fe20372bc4ed888006702d7882dd8a12d619afd70fbf1024Virustotal results 0.00%Quakbot