URLhaus Database

You are currently viewing the URLhaus database entry for https://psicologomatheuslima.com.br/rsu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660033
URL: https://psicologomatheuslima.com.br/rsu/
URL Status:Offline
Host: psicologomatheuslima.com.br
Date added:2023-06-14 09:02:21 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:04:29 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 8 hours, 42 minutes Poor (down since 2023-06-15 17:46:41 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_ED930_Jun_15.zipzip 8d6bb6f9df5437bbc3aaa89f1330330b1d783ce85746ed3ba10206bd814959c2Virustotal results 6.45% Quakbot
2023-06-15document_DB561_Jun_15.zipzip c2411d8fe7782e5db48e3702d8461cf3f8eb565f58f139b2b9f60594c7e7c034n/a Quakbot
2023-06-15document_CA480_Jun_15.zipzip eedef75c9e4577fe16cc82ae8c668aa8152d83b893dbf941504f8754317e3455n/a Quakbot
2023-06-15document_BA092_Jun_15.zipzip 0a19e71290ea7a44e13f1ee3104a0cfa06e39ee717d6ab9a6bba96c691e18de6n/a Quakbot
2023-06-15bOO9zqO578F1v.jsjs 079259c2d10d4d433baf490983016e618e0f16f2b09e80186f454f92fcd11e33n/a Quakbot
2023-06-154sQKlAJ1H60E.jsjs 4140d4d33e1a5c0ddd84e2da7e20e6259cca636700ec9ffbc0bcd66776de472aVirustotal results 13.56% 
2023-06-15KRKIy0qKM19X9.jsjs e0c2da4765fb13bb534e54b6068d50f44839769f66a9039f29bda65b86ff4061Virustotal results 15.52% Quakbot
2023-06-15EWf3vwkKPH52.jsjs 9429d24f8fdd181e9f3d22ccd607c94113c6bdd26524a2c33193c93c89dba954n/a 
2023-06-14XBzVVVvukFA79.jsjs f1e7980b1789c195200a5612a2fae7652bcbfaac5dae267c7306559a1088b6fdn/a Quakbot
2023-06-14IzaL0IFZrEwYg.jsjs 9790d513364db22c7716d1eb6a94d38bbdfdd00777cd38f12622122cf7223da7n/a Quakbot
2023-06-14hAbsAiSTUooBDP.jsjs 51c1b087a2d30e7647b929c7eed2986a3e1976ee43045a08250cd211f22b391an/a 
2023-06-14ZZrvn6j1TCC6c.jsjs 5a652761cdc46fb64dfac6c2d3d9ab2bd6108ccef5860b411746c8de1c6ccf59Virustotal results 0.00%
2023-06-14U6ViXW5xo8U44.jsjs 8c603ba6bc04adaba6517858382a405e10b5b0ac2c0457c12b265f38d1a7ab3dVirustotal results 15.25%
2023-06-14VAVPmIHCNaKTV.jsjs 0975c3c93b7f70c773fb13060f63c8d1435081c5dbd2c9f5a7d1abd4eaebafa8Virustotal results 0.00% Quakbot