URLhaus Database

You are currently viewing the URLhaus database entry for https://staffordhvacservices.com/crun20.gif which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:723962
URL: https://staffordhvacservices.com/crun20.gif
URL Status:Offline
Host: staffordhvacservices.com
Date added:2020-10-20 14:32:06 UTC
Last online:2020-10-21 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: lazyactivist192
Abuse complaint sent (?): Yes (2020-10-20 14:34:05 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:16 hours, 2 minutes Good (down since 2020-10-21 06:36:12 UTC)
Tags:exe Qakbot link qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20n/aexe 9ab404c46a4511f207c5b9df3e76c2618d193873e98ec7bc7c9e60b5dc285bd6n/aQuakBot
2020-10-20n/aexe 76ca0f3d7cc3c4231e242c4a90ecfd5da244d4df64cfc3c95da1ce321e1c3852Virustotal results 45.16%QuakBot
2020-10-20n/aexe 48f64c9177e93942695e1108b6346a1437a3ad44e6cf65ebe1d2e5b738a23421n/aQuakBot
2020-10-20n/aexe 507a5d8212197647a28afccc1a800f7e28b4c26ecf1181bac72921b95d33d83en/aQuakBot
2020-10-20n/aexe 6f00837f83703021bc4f718a4df8a7fbdadf5fff50728dc09c050efa5259db89n/aQuakBot
2020-10-20n/aexe 6e682ff56d1665e1462761e22246cd232e2e819a600d81fe0e770104c097db7fn/aQuakBot
2020-10-20n/aexe 1138aa0a51e7b7c9bd78b1b423ceec867de06c609adf541ee9f1b0168ba32121Virustotal results 43.55%QuakBot
2020-10-20n/aexe ddfcc04088a52d6ebd212390fd55c95cb7f8286e200175dad5bb5b1ffd141762n/aQuakBot
2020-10-20n/aexe f4bfb36faa1244ccb7eff5b1ede62bbdea104a86caaab19cb962f3cba093ccadn/aQuakBot
2020-10-20n/aexe c59164aae8501626379a0956e0367081d9f4bf330165f16ccffbe0da867ed169n/aQuakBot
2020-10-20n/aexe e7b71f274fa6101b23bea864a62527e991781f2b94d2158077bef3e8eefa0bc6n/aQuakBot
2020-10-20n/aexe 4a6ca274f5f152354863189c9a593bf566cf120c8d6c5b4e023ae5b953f26b5aVirustotal results 40.58%QuakBot
2020-10-20n/aexe a377d9feadbe4833a58119212059ef8ede76a06942a82c79e5f179707b5e0a2an/aQuakBot
2020-10-20n/aexe 79aca9d3f5ef2e6e73a8966187d65d9822c7c1295b35cd4c96f9a262996dc6dfn/aQuakBot
2020-10-20n/aexe 8ba3aa42d5c3e1b4cd3ead07bf2c40641e4011aac0b2a1b1262f80504d423f9an/aQuakBot