URLhaus Database

You are currently viewing the URLhaus database entry for https://imprimerie.casa/eud/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660032
URL: https://imprimerie.casa/eud/
URL Status:Offline
Host: imprimerie.casa
Date added:2023-06-14 09:02:21 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:04:28 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 7 hours, 0 minutes Poor (down since 2023-06-15 16:05:25 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BC640_Jun_15.zipzip 53f909567ee286ce1295d47e7ce22ad85182dc1bb251ebbddc2fe05813947232Virustotal results 6.45% Quakbot
2023-06-15document_AB625_Jun_15.zipzip 6cc65d7af3bd3a8bb04ee19f641d0d62d322aac4c89dc2fa57321551bfa44d15n/a Quakbot
2023-06-151xGysCILn2dM13.jsjs a8b8ca73b7e219eaa61418dcc7e17e1628b5145171686b84489e4a3b55bf9f5eVirustotal results 13.56% 
2023-06-15Ol7padTMrtZI.jsjs a4bc521cc12f23630bb1cd5953b9ba49e8b975ec60301407f6558d7bda865961Virustotal results 13.56% Quakbot
2023-06-15aLMMrd8Po5FZv.jsjs f3e5284a083b419b8905ffcbda991727ab6a23f625dcb49aae2833225cc940a0Virustotal results 15.25% Quakbot
2023-06-15CPwcxmnCxEzWYs.jsjs 643b17141fae317ca933669dbe31a07c37efdea2d30db65dc5e2dc47fb7bc9cdVirustotal results 18.97% 
2023-06-15BhorM2hI9wXtSt.jsjs 406ebad523ba66fe782171b310070307bf2d2b2db21a6af6376f05aa5ef74558Virustotal results 0.00% 
2023-06-15BeXh9flpLXZj.jsjs 1cc9b8ac64f4025144212c5262b32aa8e768e45c869f2d298de9ec726e89d1edVirustotal results 0.00% Quakbot
2023-06-14Pby9jU6hjMoF.jsjs 67ac379220c433fed2ff4305e9934f0badd65bc16f29d3a81f0ece8b8998539fVirustotal results 15.25% Quakbot
2023-06-14fcdEWJQEOyS7Vl.jsjs fd920fb95718946fd479abe84175e358528697990e15553ca4b2d8b7d0c1485fn/a Quakbot
2023-06-14ZTBmezckK5Cp9.jsjs 77ee59f5de41fe253695de13801bf06c13dedc1897fa9fb15b5b6e0635c2455bVirustotal results 0.00% Quakbot
2023-06-14lFCT0hzvyoX00.jsjs 3bbd595b90e2986fc2d5e29a671af3b529f680f4464340386790f96ed588ac17Virustotal results 0.00% Quakbot
2023-06-14U6MSn9rXAJqI.jsjs 54ad7bc778ce3705b7ac15f9b97d5772ba4c4cc997ca79f3b8f510f7ffd01e3cVirustotal results 0.00%Quakbot