URLhaus Database

You are currently viewing the URLhaus database entry for https://researchwritingexperts.com/esu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2628863
URL: https://researchwritingexperts.com/esu/
URL Status:Offline
Host: researchwritingexperts.com
Date added:2023-05-10 15:38:07 UTC
Last online:2023-05-12 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-10 15:41:33 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 6 hours, 28 minutes Poor (down since 2023-05-12 22:10:15 UTC)
Tags:BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-12Xvgqh.jsjs a4ab84fa909dd986b0c7af8e25d277f405a3073c56389c51feb5a8299f9c79a7n/a Quakbot
2023-05-12Mphzxum.jsjs c6f5fe8cf8ab23d9ac612c5ead341469f7a3ee33ae0550697ff328bcbfd49935n/a 
2023-05-12Zfnmmkgk.jsjs 5c4922237e972c15673086be00f3346ede26dc41d3cb659d2e4b809cf6c13f3dn/a Quakbot
2023-05-12Tgpfxob.jsjs d9d3272e8d25e8d3fb49d38a51a7826dfe211ec8beb36de46d7b255f8db614cfn/a Quakbot
2023-05-12Bcze.jsjs 24fdf8e3007a059068f72cf5d3504d15eef2c296d1bd798b956f8fb5aa051057n/a Quakbot
2023-05-12Aicjymuh.jsjs e8fdfdcb0616aca8bed84fc4a09c83b8ca1be90eec78a6af983730cd86f14bc5n/a Quakbot
2023-05-12Tcqew.jsjs 847f8fcc833cb5bb3c42e62d8db6267429a013e8a8715a4abbe11e1fd8b8a69cn/a Quakbot
2023-05-12Naxnayo.jsjs a9384b268164d46fc627dbb494baeab280c7fc6045fcfd7fc549eaf1bca35dfbn/a Quakbot
2023-05-12Nhjel.jsjs 580213d042f9bcec3e49113ef909dc1088ae3081e98ed9840b0771fc4e36a52en/a Quakbot
2023-05-12Bpetcmne.jsjs 899bd81176a448bab2e5b0905eb7d87b61e1e29d3ee95e5a4fa78ac69ffbc7a5n/a Quakbot
2023-05-12Zesarbix.jsjs 5619c7a49fab793033c521ba7fe1763c6b961596eafde7b07c861fa6d0ef1afbn/a Quakbot
2023-05-12Ftfnt.jsjs d2fcc6dac87298e56515ccf6411e1be7d9b321283178ef432e4381395ce0133en/a 
2023-05-12Tbnnefjf.jsjs 3a9532ae9a567adde199e188113016843ae4ac8f6fb5f634528c65f854e2669bn/a Quakbot
2023-05-11Jjplrps.jsjs 2e85f896dae5a75daf87f318604ec605e75204bd42ffac1f71b0486bbdc7adbdn/a Quakbot
2023-05-11Bgtsrxv.jsjs a015760a94fcb4c7049ee47bdf165bc60ccb2774c9d580d3065fdd37ea7546a6n/a Quakbot
2023-05-11Dbwjt.jsjs 520b62dc90747c1a866ae3d793047e1c050d00160362a7398c54d89560d04362n/a Quakbot
2023-05-11Voio.jsjs 8631fd626af486f3e56b1cf83b3119dbc4dbe11740a5ad444ebc2fcbda76b27an/a Quakbot
2023-05-11Szbx.jsjs d1ef7b7b3f3341c74949718aecf60e675debaf93b80230ed07ac71b31f07f827n/a Quakbot
2023-05-11Eows.jsjs 16d0d36db19937dd239aaca9851e6062175a13206ecdb9c494711ab66e1e04fcn/a Quakbot
2023-05-11Yzivfhf.jsjs ea35801e57600ffb832e18cf57ce3c1bc15d2170bedfea5dd49490cdcf78d44fn/a Quakbot
2023-05-11Ujmrpmqb.jsjs dc8ae1502f27a0757e6880db221d05941fd2ac423d6561414946e2546eeb3835n/a Quakbot
2023-05-11Ooct.jsjs 93983151dc0f2141c1b94c8e109fb6296ff30925d2244025e7d851bf8560de25n/a Quakbot
2023-05-11Mhenmzox.jsjs 71c3881a61c910331805048b52bf10512f4e107c782df15753dbed62ebe0cf8cn/a 
2023-05-11Kffrf.jsjs a44f325e99f28e5e3de7edfa796d8bb04e99d1b078a1d20c9498ca825d9f3e6dn/a Quakbot
2023-05-11Uhfyfiwa.jsjs 9392108aeae58ca1beebbb510eb04cd9845d45aec5ccfe9885ed104406cda3aan/a Quakbot
2023-05-11Nhaf.jsjs 0c3e08fbaab635994bf8d888238925683d531c9241531383c25135bbdb369dfbn/a 
2023-05-11Vzagymd.jsjs 29f89fef8acec2f46046aac3062ba70708d7de8971f067b85cd8842c5d2250a6n/a Quakbot
2023-05-11Mmvy.jsjs c325a813ee9fc2e572926ba6b5d1b1af2a89faaca2e6704f11e82ff5df2f7588n/a Quakbot
2023-05-10Vhko.jsjs 9abf1acc2e92254542694b79d99fa98470d4fa0bf35f0a067b9bdaa52d2b7bd3n/a Quakbot
2023-05-10Uuvqeaeg.jsjs 56dba8604491f41faade3313d9045349bb17063f5cc6b2eb944b0138c3a81056n/a Quakbot
2023-05-10Parzidxo.jsjs 0b1585ea8a13196e810fa3502053e8db8fb7ecabd1242f85c1df091a1fa525f5n/a 
2023-05-10Fragtn.jsjs 2d8c2e76832a6c630c1ebd632d1d1e903cdb8a83be49ed845d15f0aebe827edcn/a Quakbot
2023-05-10Neikw.jsjs c39e87dfb67ac92b3257eb9a1a25ddeed27c20ca341c6d93e3d8ba67d38dc0b5n/a Quakbot