URLhaus Database

You are currently viewing the URLhaus database entry for https://wcalhas.com.br/fg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660063
URL: https://wcalhas.com.br/fg/
URL Status:Offline
Host: wcalhas.com.br
Date added:2023-06-14 09:02:27 UTC
Last online:2023-06-15 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:05:07 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:23 hours, 49 minutes Good (down since 2023-06-15 08:55:06 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-14bHL8d7UabRuKGS.jsjs ddf44cef5edf4bc3ae42ad311806abede228f333c55ea1a445fcf7468645940dn/a Quakbot
2023-06-14MJx84EEKseoNB.jsjs 0ca741976863ab9777398b56775869a69960486891a638f91d8586ecd6b85d98n/a Quakbot
2023-06-14cWsmEz9lqOD1q5.jsjs 50669a04196ff01ec2c144fd6ecfd1f9b419e195fb331c9d7bb332f35409658en/a Quakbot
2023-06-14docu_ED627_Jun_14.zipzip a8fa341a4092c92e4dc493a747766e8726c2c92d4c7a894a7044040df441d369n/a Quakbot
2023-06-14jOVhmbeNbHzck.jsjs 524df894244a701b9825ef6f279a4ba64292f219614dad255858ccd503a896b3Virustotal results 15.52% Quakbot
2023-06-14VCS6wRRz5XxZ.jsjs dc380c6947c5f8de2586ab7baf30b36b6a9426932323cb2096af2c5f4e2c344dVirustotal results 15.25%Quakbot