URLhaus Database

You are currently viewing the URLhaus database entry for https://cagro.co.za/uda/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660072
URL: https://cagro.co.za/uda/
URL Status:Offline
Host: cagro.co.za
Date added:2023-06-14 09:02:31 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:05:18 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 day, 8 hours, 24 minutes Poor (down since 2023-06-15 17:29:28 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AF759_Jun_15.zipzip 9df66a0aaab76bdbb5d13c4646d7a09ab96994857259f5caf5dae315dd3f336dVirustotal results 6.45% Quakbot
2023-06-15document_BF245_Jun_15.zipzip b4ab0caa12b99e004f6f9e3e2ded8de95420ce9825660ce0e20b40a34da98b08n/a Quakbot
2023-06-15document_AF103_Jun_15.zipzip 9a7ef773608897473d7b9f44739378a59910c758998010b9607727df0b03101dn/a Quakbot
2023-06-15JWNMpQAQBP5qf.jsjs 5c0e3a21ce2f70da489980b9e18607e6dcd8d2dc62722a0f538728255e5f23cbn/a Quakbot
2023-06-153E95CoTnFmqr.jsjs 647639dc42c7699c9b70e466a55b13ad7112be63abdc425f39efa64ad3e31626Virustotal results 20.34% 
2023-06-15Ptr3ujEJCnQaX.jsjs 3ed69cee4e64a5062882527dbf4e22478e7fe172dd50cbcfc8c9af08f218d4d8n/a Quakbot
2023-06-15vBVoXQ0bdjQ5M.jsjs d1a1c1f06bdf9401f07387434ab943a04de615a34f2952bc686f96c2a7f235f7Virustotal results 23.73% Quakbot
2023-06-15tqcgs3g9rM50.jsjs 046e40d374c8e2a2147806a22e3efff9357a8551c53a66173eb8a732696450b8Virustotal results 0.00% Quakbot
2023-06-14NnUtOjtVR2RZpJ.jsjs 1a86d523c984f15bbcdb25aae07bdd5775d98b3b37a48b6c45cc541c30f864e4n/a Quakbot
2023-06-14aBkyFXlTvuJ5Z.jsjs 05af50f1ce046ff06a1b8cc460e6a4c27704dabad038cf11bf063914d46503d4n/a Quakbot
2023-06-14cBsYl1SpEZRXB.jsjs b0fc3145fa9302b8ecc84b054537ba2e4eaf362b1807ba333396aac4bb39e73bVirustotal results 0.00% Quakbot
2023-06-14DcMhV62519tEm.jsjs 3f55ba89edc7119571a5e449432a86e46db42b02a85961e11a6e63b91514cc36Virustotal results 1.69% Quakbot
2023-06-14XCeCT9FMcM9g.jsjs 1b3e3c12210767938b8b0574c31c17ac4246fefce53d0a34080a685946e8f4a8Virustotal results 0.00%Quakbot