URLhaus Database

You are currently viewing the URLhaus database entry for https://andreguimaraes.com.br/rien/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660021
URL: https://andreguimaraes.com.br/rien/
URL Status:Offline
Host: andreguimaraes.com.br
Date added:2023-06-14 09:02:19 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:04:14 UTC to hostmaster{at}registro[dot]br)
Takedown time:1 day, 6 hours, 49 minutes Poor (down since 2023-06-15 15:53:35 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AE956_Jun_15.zipzip 4ff9848b211a8f3e3e136865a27b925765e0f9b52092881f49e293ea1901d7ebVirustotal results 6.56% Quakbot
2023-06-15document_AD568_Jun_15.zipzip 2eed9a67e32e9e6f0f1b99ae7ba2dd7c8b5c9444328952c719382fdd23b4df8an/a Quakbot
2023-06-15document_AD745_Jun_15.zipzip 976e0a7e53ae7dc10ffdfbf8d08f3cba8c03ef706a48b9b58b7b906b2f60ad1cn/a 
2023-06-15KpWoIVGHwSsUQ.jsjs a94e0cda2b003321063678fbf697bfc202c870a6a1cdd8d3e2bc4ed3a1a9e93bVirustotal results 16.95% Quakbot
2023-06-15KooC1WPboBZUUV.jsjs 018852678f2d9502fc6be0119af84423805b3672bf17b806a16fe445cdc79d4dVirustotal results 0.00% 
2023-06-153dj5Uz1mdEZw6.jsjs a650d434832bdb65d710d0a91b4570dd5a466221db9970a26059558ca234170dn/a Quakbot
2023-06-1463uWoPxkDE59kX.jsjs 7a5c93c2fba3015bab7918d7073f08a0101c18fcb07a9473ae5a4ea9f0b8f1f9n/a Quakbot
2023-06-140YQlYmSCFNiM.jsjs ebec161b1dd031ca7a25c79351a5141ae66612ba6cf9fd1dc3de15cda6eecbc0Virustotal results 0.00% Quakbot
2023-06-14docu_AF280_Jun_14.zipzip 12dc825bae205621ae3213bcc8f96688306b0f380e910905cd048a80d6f91778n/a 
2023-06-14docu_ED627_Jun_14.zipzip a8fa341a4092c92e4dc493a747766e8726c2c92d4c7a894a7044040df441d369n/a Quakbot
2023-06-14U5eMkRL6CbFETE.jsjs 4573e411b70a42868e2b1d62ebddb99005c241abae8eb6652d2e1d1e3b815681Virustotal results 0.00% Quakbot
2023-06-14UaRhpQd5DFODnX.jsjs b4e17241304cddc6bb0ccb0fdcad130a8c50c007d3850e39ce6c8d3f24865201Virustotal results 0.00%Quakbot