URLhaus Database

You are currently viewing the URLhaus database entry for https://korpore.com.br/qiat/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2667426
URL: https://korpore.com.br/qiat/?1
URL Status:Offline
Host: korpore.com.br
Date added:2023-06-20 11:54:00 UTC
Last online:2023-06-22 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-21 13:33:07 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:1 day, 7 hours, 58 minutes Poor (down since 2023-06-22 21:31:39 UTC)
Tags:BB33 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-22Qfxwy.jsjs b2cd66c82679032b963aa8fca53e04d8133811f607a189b32c8c4a396e4a1ff5Virustotal results 6.78% 
2023-06-22Kwii.jsjs cff6f50981ee34ab9b8375e933271f149f9368fc7a034dfcda7cbb0480fffb49Virustotal results 1.85% 
2023-06-22Tqw.jsjs b97572e7ed709cb521cabf4501332a2c883041341098857d786234421f627a03Virustotal results 5.17% 
2023-06-22Zkr.jsjs 43a39800fc12bab54014bbedd5eff5adf55860c966afa0f5c89469c8331ff4aaVirustotal results 1.69% 
2023-06-22Cxk.jsjs 51d3087de3bd0f702b9aa2dd384d3d0521d606f0e1ebfa0e44bbd1affa9b6bbbVirustotal results 6.78% 
2023-06-22Mgwss.jsjs 865a3c72f6fd2fcdd819d6809de2a4faa99eac7455c474d9552ec98809db9ce9Virustotal results 5.17% 
2023-06-22Zzii.jsjs 824ce598503a33e07553d837d9f36bbfe959ff864659a7c150189697cd0d3b90Virustotal results 1.69% 
2023-06-22Id.jsjs 9f1ef78b110e9b6bcc59a176afb05757e7438384d61884d3831b46404c3c5905Virustotal results 0.00% 
2023-06-22Nlwmt.jsjs 33085c9597f7439d5e8d9931e818b7e5c9a35bc83fc562f75e40ef54eb0e7fe8Virustotal results 1.72% 
2023-06-22Slrm.jsjs fbac387543ec243cb6bf33e43ac939bb73f4148fe63ff463dd98dd8fe0b90b28Virustotal results 5.08% 
2023-06-22Rbdhr.jsjs dcc974d04d8475cbcb1a79c9a43b17316685f0ba2f7b61dbac2c25e93549a84bVirustotal results 5.08% 
2023-06-22Ubpd.jsjs f0c069e8fa82d76e90c5198cd659252acc2b00fb278d704e28b6ba05fa5fed73Virustotal results 1.69% 
2023-06-22Koucu.jsjs 7b6ebcd6ac51af0f1233ecb496407f8b585be7004af24d6365b9de1f69c78425Virustotal results 6.12% 
2023-06-22Aicj.jsjs 8b4d0d673e3f7bf0aba629d6bba4ab3104d47e9158f731cb9d691f630d597d63Virustotal results 3.45% 
2023-06-22Bwk.jsjs ce618fcbfa882fa04cd507640369323b88552de569710503bce116e0a1bbe52aVirustotal results 1.69% 
2023-06-22Efga.jsjs bca69e8698bb6b9e41ebfd88a553e93efd51e157d51e44c12cc6a7f859922d47Virustotal results 5.36% 
2023-06-22Wuj.jsjs bd6e6bad5ff9206e0a17d95d69bfbe1e75923d90111222f2c2074b47b07bcb0dVirustotal results 5.08% 
2023-06-22Lxi.jsjs 01ef83a83dabe4d9d25ea30f7e946d650e57a813ebd9a6a846aff69eb64991e9n/a 
2023-06-22Ueh.jsjs 7328b8c051607428e384e816a74b0eb95dae4d8d867f1c4e3079bb7beb6a97e8Virustotal results 15.25% 
2023-06-22Qhwd.jsjs 943df1071c647c621f8cedd584d3478d47956c3897934d0be91d71f3134955b8n/a 
2023-06-22Lgthy.jsjs ddf868e3995e582d8b6c81f1348c2548b891a9a9dffb39d966f42088149fa89bVirustotal results 6.78% 
2023-06-22Eqi.jsjs d7d3280dc1a7e9e6d4eabfd2851ae30243a83b3dfb15a9c87fe467736507395eVirustotal results 18.64%Quakbot
2023-06-21Fkm.jsjs 2d063af9f7f71efbab3c7c7f8badd673c0f59fa648b9bdbebdba3efdf2917219Virustotal results 1.69% 
2023-06-21Zd.jsjs ebffa69d6d003d3f68786ba7b9aefbefc023dbba61a7d3dba13bd49aa41b146dn/a 
2023-06-21Nqjx.jsjs 7483de39675118ecb5d117b20258121b672a74cb4bc60356e13e0a3046275f6bVirustotal results 1.72% 
2023-06-21Tufs.jsjs 6505f74a70b04a120db430e10efaf069de000b462545730efc0b1de802056627n/a