URLhaus Database

You are currently viewing the URLhaus database entry for http://celebridge.in/ptqsrjbebf/530340.png which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:668549
URL: http://celebridge.in/ptqsrjbebf/530340.png
URL Status:Offline
Host: celebridge.in
Date added:2020-10-08 06:03:06 UTC
Last online:2020-10-09 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-10-09 12:26:02 UTC to ipabusereport2{at}liquidnetlimited[dot]com)
Takedown time:1 hour, 50 minutes Good (down since 2020-10-09 14:16:09 UTC)
Tags:abc015 exe Qakbot link qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-09530340.pngexe 2e30e8ffc4975663b068241372de7ee035d4d7fd63d51e2ee1d24d01fb37dc53n/a QuakBot
2020-10-09530340.pngexe 95a71c1f8bf83fff33f77428eb4d4f99c73ff3b410b0aceca07db20451798716n/a QuakBot
2020-10-09530340.pngexe ad5f76e4dfd59c7a0bf68c0f7ac64fb9d40257910891406c67469908bb65d45an/a QuakBot
2020-10-09530340.pngexe f11569cfff2bc78d1bb96b6298eaa14b4c577dbdee3c6f7ed49d82ae59b9c048n/a QuakBot