URLhaus Database

You are currently viewing the URLhaus database entry for https://decoblinds.com.mx/tiud/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660026
URL: https://decoblinds.com.mx/tiud/
URL Status:Offline
Host: decoblinds.com.mx
Date added:2023-06-14 09:02:20 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:04:20 UTC to abuse{at}dimenoc[dot]com)
Takedown time:1 day, 6 hours, 58 minutes Poor (down since 2023-06-15 16:02:42 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_EC645_Jun_15.zipzip 78d9d25eab4952a106cfaa0c72f3151fd46e52722b1872c4a4797618090aa398n/a Quakbot
2023-06-15document_FB971_Jun_15.zipzip 188db66a427d5a7bb5da40db8fa1850df8748cd8086ca936b22bf9aca29e7aaan/a Quakbot
2023-06-151fpxPISvbAc9G.jsjs 0805a993b45288ff38155e7b79b3a731d610eb755350c23b4bef1bfe38af95dan/a 
2023-06-15hm5KFshB52CE.jsjs d29d26ad6c6f4e41c67e00adf68f3a8591a9f2f25581825d67ce4b99ac5e49a7n/a Quakbot
2023-06-15KNu7Xf1WW2Ez.jsjs e71f19f85e17db513031fa507a3eab519cf0f879d602a71c80150e081b544feeVirustotal results 0.00% Quakbot
2023-06-15y2K8D0zEJ0K1.jsjs 71bdcfc4e5d0a656618d24c89c5b7634e4d07d6925c4fb316065e7c019b640e9Virustotal results 8.47% Quakbot
2023-06-14kDTmYaeybXXyz.jsjs 3a9c18e162dab5be3f18ffcbe20580c8603e31b77358d2bd92c35052377d0259Virustotal results 0.00% Quakbot
2023-06-142Pz8Acpsjk7Bn.jsjs 58de161df08bdf30091c7dcb65e2a6f988bda01679375d43c8c8a974e545195eVirustotal results 0.00% Quakbot
2023-06-14nUTiUzVd50hP.jsjs ad154d2892bc10ee9562efd6c45f18437c65db0f809c792d414ad926ed229488n/a Quakbot
2023-06-14V0HdWsxTeHez3.jsjs e43fce049074b91782ec0c826b7ce89402dfed3053e23b15d8472264b63ebbc8Virustotal results 0.00%Quakbot
2023-06-14zvOk79GM7Ib67.jsjs e54de6391dc3d071895ce3b79273e61dccfbffb8d7584f04399258601d5ee4b6Virustotal results 1.69% Quakbot
2023-06-14TsqTU9pfILynDP.jsjs 0c21520790a4f916213684fcdd904aea5ce48528eb25843c7eafd8c9bd706f3eVirustotal results 0.00%Quakbot