URLhaus Database

You are currently viewing the URLhaus database entry for https://visaexpressbd.com/qcam/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2628849
URL: https://visaexpressbd.com/qcam/
URL Status:Offline
Host: visaexpressbd.com
Date added:2023-05-10 15:38:05 UTC
Last online:2023-05-12 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-10 15:41:21 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 6 hours, 44 minutes Poor (down since 2023-05-12 22:25:51 UTC)
Tags:BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-12Ffpa.jsjs 7b6151097ab4368a4727e1e09c4602898d7de0c5877e6e72ebded3a139d1fbfen/a Quakbot
2023-05-12Ktjzthsm.jsjs 419466c674529e67b1cb43c68b655c0bcf80de388a17cdc5f9c36cea2403ea4bn/a Quakbot
2023-05-12Zcvhwkb.jsjs e1620dee3a9b414bdcbc8f34646e6192c969edb7babd952bd29a406f0eacaf2dn/a Quakbot
2023-05-12Ldvczy.jsjs fa8a36dda3d3caaf1a75ac4e5ccfa901a717cd893203d34792a1c562f180eb3bn/a Quakbot
2023-05-12Jiwq.jsjs 12f64301daea1d82c13fe0c89951081ba6b1c2a473b6cba0e835ef7085f9ba97n/a Quakbot
2023-05-12Gurfubtm.jsjs 1e1e6cdf5521f775cc61f1dfeb4dbdf6900789bd437201e0c11c1d0bfad7585bn/a 
2023-05-12Vqnmh.jsjs 1f9773f8db29c07e77587ab7aaaf3b9b7a1a94d1438da8c7decd593e9110b58en/a Quakbot
2023-05-12Utpkjkp.jsjs 5471892d7e5f3745a036b770aa6170b37a070262a6f8b83d0b0718f3bf12c2c1n/a 
2023-05-12Efyoso.jsjs 07dbe487639f14acb1f62c577949e823e1977e68ce43caa2d815b4e375119d88n/a Quakbot
2023-05-12Vygva.jsjs ef119523601b7f078708601ff58eb221ecf84249ec63ea3dbff3d42135548bc0n/a Quakbot
2023-05-12Vppnzqli.jsjs f5da44b2c9b38a43ada1e93c53c56d8253c8c083f4768fbe45a79cc6ca8d89f0n/a Quakbot
2023-05-12Cwvaie.jsjs 2739ebe9bab38ea3173e21f80a6db3859750dcfc589cda4524a6bccc13a9649bn/a Quakbot
2023-05-12Legnr.jsjs 14af4e6705fd637dad077696b5c3cf64e991a16f21a4e42b56a0d0c2002a0be0n/a Quakbot
2023-05-11Zgxnzik.jsjs b3ef9764dd908a9ccf7c7ca562a2561f694aa702613c91da3c5f4b6ec7617eccn/a Quakbot
2023-05-11Yjjqh.jsjs e34f060a285ce1eeef343ea8fd5c5f16bb2e163b27963015eb6b82df3419fc89n/a Quakbot
2023-05-11Mkyoe.jsjs 1ed22d5040dcfd7cc16b09c51e580a234610ac35848421852bed91ef4e93f605n/a Quakbot
2023-05-11Jliietkf.jsjs 695234ef7033c8bb4d26c5a8cbacf45e12b25236453c27c0c6fcd1783951127bn/a Quakbot
2023-05-11Bcxx.jsjs 00553f66a25622adb64371f99e3c21b4a0e642aa76c87c4aed4a04233082038fn/a Quakbot
2023-05-11Mavwil.jsjs 499a7ace20bfc9403be449a6d8486a11f8f3ce61ec2d28f18ddeb9c2ca472d09n/a Quakbot
2023-05-11Iggvmgxk.jsjs 32bba693d1ec1984939b82adc0bc0c0cd90565bf4829264518079f05be8656d8n/a Quakbot
2023-05-11Qjqnbuld.jsjs 65e008bd7de597db187886c4903dc4f1a96b1e1cc26b89befde503db129cb3f9n/a Quakbot
2023-05-11Oqarfs.jsjs fdc970bdb0a3194c242fe5a438f3348ed61a0a262e2fc4f6afb561fbf32bd628n/a Quakbot
2023-05-11Kaoud.jsjs 45eb45919680f5f3dffa6c3c65fb3343202e57e5aba7cf11166779d94a999c2en/a Quakbot
2023-05-11Nnlcad.jsjs 6c0cdfbedcd1c08f8035865ff8d30cd2de34c81373f4ab898bd1818bd7119462n/a Quakbot
2023-05-11Qiizkobg.jsjs 4a6135fa2ec467c225df5b0cc2d93112770834a8629e0eaa4cf01cf7827753b9n/a Quakbot
2023-05-11Mfpc.jsjs 8e952ba0bb3e526f6223ee7433e95727b5a0003882b9c41c813e69cbd19cca42n/a Quakbot
2023-05-11Vhtmkxzp.jsjs a6c42e98201130c527fda2ce5865738eb930b75221a540aa3f4fef662f5c0f08n/a Quakbot
2023-05-10Srluk.jsjs b524231d408132e5137a70d6ee8fda97df5d536766dde4c519e6695248c51e39n/a Quakbot
2023-05-10Iikimps.jsjs 2b50082581de22d8f10a2c07a183c7a138470c9415ef928b4b00c9984484665bn/a Quakbot
2023-05-10Aapvgrcz.jsjs 2ab425563ea882c5c2018b0e09edad3a5a6c8db427031daa9873e045dc482968n/a Quakbot
2023-05-10Ewhvrf.jsjs 755c1596a7c0d342c9933d7ecc7c1178ee46652413bc00b1937940760e7ac013n/a Quakbot
2023-05-10Fwtns.jsjs 1e1414d4e82ae67158c7f0c893a01a753e266bdfd803b70f533339849b2c21e3n/a Quakbot
2023-05-10Lmzah.jsjs f63b26c43fe7f4b85b1bc4707952124d1c4b939145597fe5e3be25722e6da770n/a Quakbot