URLhaus Database

You are currently viewing the URLhaus database entry for https://meuniversal.com/ctot/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660810
URL: https://meuniversal.com/ctot/?1
URL Status:Offline
Host: meuniversal.com
Date added:2023-06-14 16:56:21 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100133769 created on 2023-06-15 05:14:03 UTC)
Takedown time:10 hours, 50 minutes Good (down since 2023-06-15 16:04:17 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_EA794_Jun_15.zipzip e91238cc98b49a91a40e8d96267ecc1d93546be90f287f2d924a75bd87f6838an/a Quakbot
2023-06-15document_AD784_Jun_15.zipzip fb668710885ec199ca9961599650b96aac183f192e31029d8f1497094588baacn/a Quakbot
2023-06-15JFDs15urY72qy.jsjs 39b0f2054233369877bd68484752318492bdb1a832bb50d9d8f6fa6f0c85a7d9Virustotal results 14.55% Quakbot
2023-06-15mWwQ1cadWQaW.jsjs c8ecdab83e59c90c84ba068010c7346124f6006f4c44731ba219f3399fa2f9b6n/a Quakbot
2023-06-15OHrflEAhMnRg.jsjs cde640a9b9f37320993ef33fe15f981f4db5eeefe3103c94830cff91bf46bba4n/a Quakbot
2023-06-15yG0Hf1UrCJfrf.jsjs 15d5c67b7a057801e7b260917fba4d0dd7984b94d399643979b990f89c6907a8Virustotal results 0.00% Quakbot
2023-06-155qSP8iImz2PNp.jsjs 81e1be1bdc0f9d878e30123eb5544e5de86e0fa4df0cadfc988b8b9b62467a1bVirustotal results 3.39% Quakbot
2023-06-15741heM8x8zfK.jsjs 568c5131aa2d7a38f534a5d142c71d97642138c1df78f0faf6f78af6738f30d0n/a