URLhaus Database

You are currently viewing the URLhaus database entry for https://pianoguide.co.zw/qri/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659993
URL: https://pianoguide.co.zw/qri/
URL Status:Offline
Host: pianoguide.co.zw
Date added:2023-06-14 09:02:13 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:03:42 UTC to abuse{at}us[dot]leaseweb[dot]com)
Takedown time:1 day, 8 hours, 38 minutes Poor (down since 2023-06-15 17:42:09 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AC957_Jun_15.zipzip 9bb10ab2ca5a754c3594d68d7bcbecb438777d1d2f5c08050125c3fb444f8fdfn/a Quakbot
2023-06-15document_EF180_Jun_15.zipzip 409c8be53e43a86e9cf340ff6573a9753f4f7e0626445c788766f8014dc1e0a1Virustotal results 6.45% 
2023-06-15document_EB520_Jun_15.zipzip 246c349ae264681ce85985b8dba2e5efe08361ac8d74bc1a51ea9f956b1d9772n/a Quakbot
2023-06-15document_BE162_Jun_15.zipzip be85a7fa8ddf0e5fc3a5ac8ad66dc2f7898fb8c115aa8c9b4fcf4fdd8bb66d8bn/a 
2023-06-15PoQl3lHTJ68Ln.jsjs 4ce5d61c71ae6ba7f70ab15d21ba350d3f1026d55afadf73af13a6133926533fn/a Quakbot
2023-06-15y2K8D0zEJ0K1.jsjs 71bdcfc4e5d0a656618d24c89c5b7634e4d07d6925c4fb316065e7c019b640e9Virustotal results 8.47% Quakbot
2023-06-15cwfEfRJW46WOnp.jsjs 47d5b6e6169427e058adbf2d7a4a30dce28a318e599c537a67a198d7d638ca35Virustotal results 0.00% Quakbot
2023-06-140ZGW0KuIk8Jquq.jsjs 8555eaf3f4fea92d2616f6ee5dbb69f2df7b3275c3ecc975e8f825748c4195e2n/a Quakbot
2023-06-14vfuq3hmcnOn1dX.jsjs 99fa9e5fd390415cf8f49b0a746898dda4a85188b38e0b1b847d737ac7271895n/a Quakbot
2023-06-14docu_CF317_Jun_14.zipzip 6251251ad5b29b55e0db99d25623ea8670af55a22c80dcb2ed4c4cdac9a7567en/a Quakbot
2023-06-14docu_DF631_Jun_14.zipzip dfe99e49909839abaa99142b09b1e8eaf4d5ceb9e5880e75b045fc2c805c4f7en/aQuakbot
2023-06-14mDgMV7X5hkmM.jsjs b736c670ebb499c19a6469521b4f75793a2f201e8699e6889dce29e131264890Virustotal results 0.00% Quakbot
2023-06-14TKsZ61VHW1Qmlk.jsjs fbe947c2c15af059ff9859815330958f930174d5c0a7ade3ffa2ba0383910c3cVirustotal results 0.00% Quakbot