URLhaus Database

You are currently viewing the URLhaus database entry for http://halalcosmetics.uz/ds/2112.gif which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:935713
URL: http://halalcosmetics.uz/ds/2112.gif
URL Status:Offline
Host: halalcosmetics.uz
Date added:2020-12-21 16:03:40 UTC
Last online:2020-12-23 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: lazyactivist192
Abuse complaint sent (?): Yes (2020-12-21 16:04:04 UTC to greg{at}uzsci[dot]net)
Takedown time:1 day, 23 hours, 58 minutes Poor (down since 2020-12-23 16:02:06 UTC)
Tags:dll Qakbot link qbot link Quakbot link SilentBuilder tr02

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23n/adll 794d938a3bd3bd0d0455b8eca5428910893f177f5349183e657d4d3fc66589e9n/a QuakBot
2020-12-22n/adll 1e617483ef0b3de4ea1e74494200c9503947ea5a31c05eb01e14454fb78edaa2Virustotal results 21.74% Quakbot
2020-12-22n/adll a8d05281494b3dcf948c088d7cceb67a7374dc90e4dfb0a37346b937fef8360cn/a Quakbot
2020-12-22n/adll bcbd804aff1a584011f23f6f95d3dc5e59c4f2341236ec6967fa3c29699d09e6n/aQuakbot
2020-12-21n/aexe fc7a4edf9d9984d4a53b4296f0d0160436144bc5631b8c5b445a86f3bfa9ff61Virustotal results 25.71%Quakbot
2020-12-21n/adll 61309261b0c334fcba92e143659d0a6e1df40f80c5f726bc570ea01024778314n/a Quakbot