URLhaus Database

You are currently viewing the URLhaus database entry for https://admvanzin.com.br/nun/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660043
URL: https://admvanzin.com.br/nun/
URL Status:Offline
Host: admvanzin.com.br
Date added:2023-06-14 09:02:23 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:04:41 UTC to hostmaster{at}registro[dot]br)
Takedown time:1 day, 7 hours, 52 minutes Poor (down since 2023-06-15 16:56:50 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_DA759_Jun_15.zipzip 78e407ded41e1801213834a391ae9b65a00419ac1c4265542fc7d2425cf06297Virustotal results 6.45% Quakbot
2023-06-15document_EC209_Jun_15.zipzip d194f8781e9adb399f749557d40a1046bf902631cc0f902d6ac39bb2c81321dcn/a Quakbot
2023-06-15document_ED917_Jun_15.zipzip 9c8cf06698e91db48b48a9f0a4a4cd2a36dba098173c6e852015e032b84bf51cn/a Quakbot
2023-06-15DlSfHBx9tUpMl.jsjs 07ce4305da692406f27a31e85d2ea9b4a92824e0b46c612943aac2e71a77677dn/a Quakbot
2023-06-155UnLQEL2uwJjc.jsjs adf944c592b6f4738467861010f5e394a3e8d9ad267eafc217ffc31623446f93n/a Quakbot
2023-06-15KHrPbXdCMiWU.jsjs adcda4de90068192f647c4ffa8e3e9a7b5423339da77d3dcad6fb60676787c05Virustotal results 18.64% Quakbot
2023-06-15znYrnl2hYNzd4.jsjs b9ba18efb01ed29b8c912c732ce28d88fd9f972a928ee17e6702e32f95a5d8d3Virustotal results 0.00% Quakbot
2023-06-15PBEZz3iNjB9kFp.jsjs 72d2ce2ffa0a9c48f9bd2f0c4b30d9adc446eba30a39e75f589676ba74cc10a3Virustotal results 5.00% Quakbot
2023-06-14otWI2oXSHhPtdn.jsjs 7cc3dfda505987eb22999b4130a50f4de888dbd18fca3f713c6ca6540de12ce9n/a Quakbot
2023-06-14HC95Y2LLkruov.jsjs 110393ec719c33e29e3fee10269b34f36bed3ca69d65c73bd94f0dc63cd47494Virustotal results 0.00% 
2023-06-14p4nfhfa86etuI1.jsjs a48319da93d613f7d0233f8c9bf0d69e24aef9abce3332a731dc1f4d86c3b102n/a Quakbot
2023-06-14V4W7Hf5zwlDL17.jsjs 2a406608a0ffaba2656cf5879e23dfbe00108787515fb0cf28a1f28ba8b06c94Virustotal results 1.69%Quakbot
2023-06-14QgESjgbpGKkhH.jsjs 4cd6bc069b81021c3b56442462430313db02a21be7b4097bda5b59bb18623e0bVirustotal results 0.00% Quakbot
2023-06-14U6ViXW5xo8U44.jsjs 8c603ba6bc04adaba6517858382a405e10b5b0ac2c0457c12b265f38d1a7ab3dVirustotal results 15.25%