URLhaus Database

You are currently viewing the URLhaus database entry for https://actiglass.fr/plui/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2628991
URL: https://actiglass.fr/plui/
URL Status:Offline
Host: actiglass.fr
Date added:2023-05-10 17:10:11 UTC
Last online:2023-05-13 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-10 17:11:09 UTC to abuse{at}lws[dot]fr)
Takedown time:2 days, 12 hours, 5 minutes Poor (down since 2023-05-13 05:16:40 UTC)
Tags:BB27 geofenced js Qakbot link qbot link Quakbot link TR USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-12Svpyo.jsjs 9b360b3ff4fbb848ff407b48a97cb3b4b95a8b102b776aefdda3fb1b45d577ben/a 
2023-05-12Cqdxu.jsjs 370be9649aaee0903aba25b22c766cef0fb119d738900c0bf460ff1de135598an/a Quakbot
2023-05-11Exevzh.jsjs d3af5fb4666e2a7e79b1a201efa2c868c561c746e1e1ba362ff69a477d22bf80n/a Quakbot
2023-05-11Fmzeh.jsjs 2f4ed482533667c9353424306a11e1a423e67424da9b05e7153137053695f38fn/a Quakbot
2023-05-10Qaqjzcze.jsjs 650582a117f9c9de86532b5e0591a8be39bd9ecd03c66851caafe970cd53b565n/a 
2023-05-10Tpcmhih.jsjs 38855f3b690734ac3a363fcf3a192fa5b55ebe220ebbcff42acbe21f7fe5b0bfn/a Quakbot