URLhaus Database

You are currently viewing the URLhaus database entry for https://gpshelpline.com/toc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2628665
URL: https://gpshelpline.com/toc/
URL Status:Offline
Host: gpshelpline.com
Date added:2023-05-10 15:37:16 UTC
Last online:2023-05-12 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-10 18:30:16 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 6 hours, 6 minutes Poor (down since 2023-05-12 21:45:17 UTC)
Tags:BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-12Pfqb.jsjs f5678477fc9b4764e5ad2b86c43967aef05da51cd8540a8f47f3da1a8c0d6d4en/a Quakbot
2023-05-12Dddl.jsjs 35aa40f22a0f2acc73f4fd645996d16d48a1ff1b5b5daa08132580e4813d7995n/a 
2023-05-12Orhvb.jsjs 6fd42a87983d10bb1201eb2da9261ce49befe9b890a4a5b1d5102152deb3b432n/a Quakbot
2023-05-12Fhupm.jsjs c498741e2421e9025d61b4bd6c86cf4e9952b4c85ca23e3e914733a44aa2a3f0n/a Quakbot
2023-05-12Yvtkk.jsjs 6a59d8e18a9bc6f8855b870a730934006d30eaf519309dc277b0aaf5961841e1n/a Quakbot
2023-05-12Gylum.jsjs 121cf46558311f2a7250f46a81c945a4966656f5f15f22de6e202fbad4ba4562n/a Quakbot
2023-05-12Gmoty.jsjs 1ff2459b25905f786ed26029323a99628ab0530830ab110acd864e0edaeced74n/a Quakbot
2023-05-12Ycsfea.jsjs c08bce4a0700a837c143cb3a575e99c29a246dd352559f62dd8fcef436d4fb2bn/a Quakbot
2023-05-12Xhbapqu.jsjs f9e7468c96d756723b3c98acb07a1ec1cf46b94f1491577405bb365b6384562an/a Quakbot
2023-05-12Oeiify.jsjs 230bd0c6a6e4edb505d683eb9f03d00d3709c29e1b377a71fcb640f7d0ac2c16n/a Quakbot
2023-05-12Nprfazsu.jsjs bcc5b17caa39266b3e0cb38366a1b9268c6b2d46748cb8bf6fc2abd541ecdf37n/a Quakbot
2023-05-12Vjyj.jsjs 5410d2ad48f6e2f74caeeadd319d9952b071b991eb6aac27f88f419d9186f32an/a Quakbot
2023-05-12Xbwudfqs.jsjs ee1cd51aaa40a3176b2d4397b7b3554331956e8f66cc29dc920e07054d271e75n/a Quakbot
2023-05-12Kncwfysq.jsjs 71e9c1762bb90deef9a3c6b35c4f89d4f2ecaaa0bb9096d642a0d751be6cd633n/a Quakbot
2023-05-11Phlzdu.jsjs 8bf70679b9fa1fe8469045b90cc118ef4388f5f0eb918c0e65dca218892111a6n/a Quakbot
2023-05-11Ynokgv.jsjs ccebf258ddf8dc3b94cca55758f13d9b3b41fe9735c417be94f56c0f451fc1fan/a Quakbot
2023-05-11Ylatz.jsjs 549b8a162e7d2346ae237d153d6b6c09b1c700dc61f07656487f01c0c64b6a53n/a Quakbot
2023-05-11Sglpewv.jsjs 5ce0fcdf2e27dd25b2c9f09127f3a6597ddc191bc10871afc2cde6698713042bn/a Quakbot
2023-05-11Lmic.jsjs f555eb92f26d831f1043e14e90a4e2fa1a741b06a4d9b778d0300f3c0fafd516n/a Quakbot
2023-05-11Qpjwob.jsjs 0082530f9fed39aed347699ab62074d3c5879cdb5cec4055187cfc04dda83a33n/a Quakbot
2023-05-11Yfgdj.jsjs c5cb829cfc43520b5a606b4bfd567c326c0bf1ddf0589ceca277546bdf52e4f6n/a 
2023-05-11Xfgw.jsjs 19e5c2def2d3967155704e5931f9f48020d4fd7867dd59fc648225484a6eb8bbn/a Quakbot
2023-05-11Coay.jsjs fbd0c67402ea45ec830647be58f19ff63912348e140e856ae8f3859498a337een/a 
2023-05-11Iphu.jsjs fa9ab74e98d7bc3f34d51e5c39f16fce3895d0301b465c8db757d66fe5376d11n/a Quakbot
2023-05-11Wwsclic.jsjs 312c0cbb39eff817df0f42c519696a153e467c1b9bb83f53bb30f9871207cf8bn/a Quakbot
2023-05-11Ldkuc.jsjs b363e29c31ec632e093c0846421ac08cabae704be7f71e4978de3a3d345407e8n/a Quakbot
2023-05-11Xuoczx.jsjs b9845e83d217d1db42f0ab1260cd1886ef8d1f7032c9f55cd98ca40cad2924f6n/a 
2023-05-11Ohqu.jsjs 7c0eff281bcd44c6b5baae8736d1b4c8ba4df8b501918154ef0bceced7e3695an/a Quakbot
2023-05-10Pqqytmv.jsjs 7ba608642e7f98d19a3ec923230ef347045d6f8f294c28796ecb141d8a767a87n/a Quakbot
2023-05-10Emjtxh.jsjs b9be0f55bfdeaeba51f10f26b48355c432c792bc1996f73f26e2a486bd2edb2cn/a Quakbot
2023-05-10Bwdcfel.jsjs 4b488a839df6dd7210dc4c10c9d787b85367cfb8229a95694e3d1b1467d686e5n/a Quakbot
2023-05-10Vugzak.jsjs aca22abacf40c930e9d82b17cc4744b6e44f281a4554b642e1da5a4720fc136fn/a Quakbot
2023-05-10Xfhenzz.jsjs c720b32bacbf9a2f3605a50b084df686962d42d019a5d1606e72fcd1060fbd73n/a Quakbot