URLhaus Database

You are currently viewing the URLhaus database entry for https://xpia-i.com/ifif/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2628603
URL: https://xpia-i.com/ifif/
URL Status:Offline
Host: xpia-i.com
Date added:2023-05-10 15:08:51 UTC
Last online:2023-05-12 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100113317 created on 2023-05-10 15:09:44 UTC)
Takedown time:2 days, 6 hours, 47 minutes Poor (down since 2023-05-12 21:56:56 UTC)
Tags:BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-12Lomqmzed.jsjs c128cc04a465384ffd8755ee462f5ac18fd5d7ef226677c06ff2a80cfd87bc59n/a Quakbot
2023-05-12Tauzcgm.jsjs 44e5c6ba188f9e9408816825a4ce03d6e2490aef194fbe4f27dcb1a7f76a3223n/a Quakbot
2023-05-12Mnrbfp.jsjs d624523f5648412eff6d5b1a219e5ee45cc6a2bbf6e9271673c76da0424e2f38n/a Quakbot
2023-05-12Tlajtqvo.jsjs cdb4fc3f08b4ac872d51d0726cca950882cf206d366e223f811b996286bba76an/a 
2023-05-12Cxhu.jsjs 891dfcaa1ba067efcad388dfed14538f5a4f2482fe5d69babb1284ef9d5741abn/a Quakbot
2023-05-12Gqqouz.jsjs 7e25bb0d728f4e640746b07ec9cf575826ffe5197eae556594a9d643f5db9c66n/a Quakbot
2023-05-12Hcmc.jsjs 27839fea2e8845cfa0cbc96c296dad76b0575e521bcbd9979f60c027d7f1f872n/a Quakbot
2023-05-12Rddqhv.jsjs ba177643960a1006ac7cc04db8d4349e4f81c24f6973348015e6dfcf6cf481d2n/a Quakbot
2023-05-12Uznku.jsjs 2ef3661147764e961dbc8afa13087d611a9e1dfa276fc3dfc86c06b6d9255778n/a Quakbot
2023-05-12Tnavkz.jsjs 74623ac7d72e0ea5ed9d15c25dbf8e7baf3a1b192c4d63a1304222943c78c9efn/a Quakbot
2023-05-12Weiart.jsjs f9c5bda8d4dfee3be26377e04edc968352c743a4dd2b9033459242cb8989bed2n/a Quakbot
2023-05-12Uvfjcnbi.jsjs e6d58a214ecfb37a8220156be40bb054554c8f627559fb495282a2b6cd372177n/a Quakbot
2023-05-12Dpiry.jsjs 3555d856415724f12fa3541dfaa5f6329298858cb2115b45f60d3b460322b432n/a Quakbot
2023-05-12Phynv.jsjs 60c49fe4303c54e208534c04d206182b2bf74b8c2415ad6945e8d53ef0d43969n/a 
2023-05-11Ajwysusd.jsjs f46e710b93a11d30dd617278b6abc9f08cf834fbd35a82592550f9e4b3cb5959n/a Quakbot
2023-05-11Smuee.jsjs 5402836ab879e300e50407cc2d9ad58157a918879d91f9cee90c1def1094061en/a Quakbot
2023-05-11Qpuw.jsjs 8b1cb714696b7c378116301087ff5672b7b2309a62d2815c6b6392c002cb0392n/a Quakbot
2023-05-11Qphe.jsjs 7a4101923b3324d63876bc363ee116dbd48f31a5690ef35cfd72bea76cfadb56n/a 
2023-05-11Cmsj.jsjs ae04bbcd6ed4499f0a0a9bd6f136130046dc9a2ce89d27a3e2f1a94ab1713f63n/a Quakbot
2023-05-11Qemawq.jsjs d8c8c1c5f8d9693f33032bce48b5f44423e61969d794e9ef4aac4066c3055b2dn/a Quakbot
2023-05-11Fhhhhahd.jsjs 545f0df28495322bacc49a25882e7001333655eac0d2af094ed49d61f92c25dan/a 
2023-05-11Coyjguk.jsjs c98b69fee2b30437a6d3f518e5f698a792322743da96bd939b6633013bb42bc4n/a Quakbot
2023-05-11Hscgrd.jsjs 8965e18e4bb4c58789512774cb220012423d796345b1341855069d2a764953d2n/a Quakbot
2023-05-11Xwmra.jsjs a2b799d8171ccf5d26e43c6458d9533fdc5a63f40a8ce0291c3dbc3874791950n/a Quakbot
2023-05-11Zgjbiaee.jsjs e376d6d56dc8550f70894b46ec4abcf5cd24febac4ffea6115447c46c94fc22dn/a Quakbot
2023-05-11Rjddig.jsjs c82c650bc01f20cebfde00d31637f35204f90a7b8384f96113ea00399c83fe98n/a Quakbot
2023-05-11Qdbg.jsjs 51df0e62c907a7f6eb292ab465d6d09f96e5a69364eda80187ddb77209d736een/a 
2023-05-10Npcw.jsjs fc1883c303b26e31a91f06bb3f199e2036622a61f40716b1e076c6797f34d61fn/a Quakbot
2023-05-10Opbzdeat.jsjs 6deb6c689e36d46805be1159c22a9c8e081445be2b34d0117bafe7728b94f545n/a 
2023-05-10Xxzs.jsjs e472e9e98d5fd01d1bf5b76c9581f24c4a9c61c89baa94bcd03cb88e63150e7bn/a Quakbot
2023-05-10Zqfzh.jsjs 71ff452fe5aa43b8206cafbadae4da7b648707861b7a34e45b5935e236d46cf4n/a Quakbot
2023-05-10Ophzshpt.jsjs 2c72c32685318ccc364cddc6dd1fea1a5ac678d267e2021d8c81972098d6ff91n/a Quakbot