URLhaus Database

You are currently viewing the URLhaus database entry for https://pricelala.com/ms/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2629178
URL: https://pricelala.com/ms/
URL Status:Offline
Host: pricelala.com
Date added:2023-05-10 17:15:14 UTC
Last online:2023-05-13 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-10 17:17:13 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 12 hours, 13 minutes Poor (down since 2023-05-13 05:31:07 UTC)
Tags:BB27 geofenced js Qakbot link qbot link Quakbot link TR USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-12Gvrzv.jsjs ae825c71e9296e5addb8b0acf69c6d3327ebfc9ba6a3917995e26e9b8f418900n/a 
2023-05-12Xfymo.jsjs 418065764d7a73e6d12fbbd7c5b63836eba8e5ecefb5f956f1645af82db0bec7n/a Quakbot
2023-05-11Nrpvbe.jsjs 1044c4fe8ebfdd1ff2bb0639874a6039525a3e7c589e12997b9eb130576082c9n/a Quakbot
2023-05-11Dfkb.jsjs 0731cac348a00864c6d3fab3440afa473ba7a438637b6885365fd68ec03f6c3en/a 
2023-05-10Ekkh.jsjs 3106351f8127804335c852644e1b4869c1933c80724e7e656f29f2f5dae27458n/a Quakbot
2023-05-10Nmcyel.jsjs 668392551cf964f5c7d49fe91ef20d26cd6c18cfaa1f99ac3ac0b5b676d7723bn/a