URLhaus Database

You are currently viewing the URLhaus database entry for https://zhtecnologia.com.br/tuut/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659995
URL: https://zhtecnologia.com.br/tuut/
URL Status:Offline
Host: zhtecnologia.com.br
Date added:2023-06-14 09:02:13 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:03:44 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:1 day, 7 hours, 51 minutes Poor (down since 2023-06-15 16:54:57 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AD028_Jun_15.zipzip dff6774c982d6a80f66b70f113678b7cdb39c9715fb71d8c0a49f7328eca1304Virustotal results 6.45% Quakbot
2023-06-15document_DF825_Jun_15.zipzip 6a0292958632464468449a81d7be7e6093a159a71d9183c349586b20a30c748aVirustotal results 6.45% Quakbot
2023-06-15document_DA459_Jun_15.zipzip a6222d810e05f79eded74de30f3653283eab59291ffecbd86fc49bd92ece650an/a Quakbot
2023-06-15cl5YB35ngYFe.jsjs 2df7157bb253035dd91d90bddce097c27e88c4ab950ac69faa706924444c1917n/a Quakbot
2023-06-155yKZLBmRy9v1Kw.jsjs 2361d8d93137a10c521d989a2d0c61b0af2fadf429598dd3a21874e4002aff1bn/a Quakbot
2023-06-15EmiITLQDeg752.jsjs fd280024cb96a583dca77ce877393b1bc6bb5e67ffc788482706918b0b57c255n/a Quakbot
2023-06-15JywZNHbWYP3oH.jsjs e5fb873ad2830cb6352cf85189daa7043bde8b3def2a410d3a8933a2c836be70n/a Quakbot
2023-06-15D4T7kt6tbamwb.jsjs 761292bd5784a1e0043b8d3e189f301625b7ca36888744445f080f141f1c5c0aVirustotal results 0.00% 
2023-06-15Wxr6pPqs0HvO.jsjs c794b2e036f5171b8f2b07bc32d96277fe93c418d3680ea8040c76f5c1995928Virustotal results 0.00% Quakbot
2023-06-14D3UQYcgYaQo41.jsjs 2f7e78063ccf8f85fcf855c84b4a3b7de5bda1500b63f2c3f2af5bc5d610dfd7Virustotal results 0.00% Quakbot
2023-06-14WBfyqh1NgzLI.jsjs 98ccb18f8178480033dd06995f8d11720e39c00e87fc58142a00125928c9d557n/a Quakbot
2023-06-14docu_AE102_Jun_14.zipzip 8a837112ef73a8a78f955507e58a416f9729e98716dada2167305c9cfa36cdccn/a Quakbot
2023-06-14u3jIQA7fHBNq.jsjs 4fa3955ad3677033ade1901e10159ac931bb4edd0daf806a2bdef0b7b509b963Virustotal results 16.95% Quakbot
2023-06-14RF6RkjbXoHHSH.jsjs cb3e1f933184aa926916c16ca694a0999fe40084d1e5c337e8701a14e1945398Virustotal results 0.00%Quakbot