URLhaus Database

You are currently viewing the URLhaus database entry for https://rossandmorrison.com/dr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2629709
URL: https://rossandmorrison.com/dr/
URL Status:Offline
Host: rossandmorrison.com
Date added:2023-05-11 11:58:12 UTC
Last online:2023-05-13 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-11 11:59:44 UTC to abuse{at}hostpapasupport[dot]com,net-abuse{at}hostpapa[dot]com)
Takedown time:2 days, 10 hours, 3 minutes Poor (down since 2023-05-13 22:02:55 UTC)
Tags:BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-13Itzpg.jsjs b52281fc2c6bcc41bd92ce36fabbdfecf876037ba714f75c7d022a3bc6c2e248n/a Quakbot
2023-05-13Awpwdon.jsjs 9684280b8927d3192caa94933ff2610d580f5721a0ccb45a46c80b20c6cbe00en/a Quakbot
2023-05-13Zsvdird.jsjs 19181c4584db930fa3a6f825551551f2e26cd9514163538232bcadb43c28678cn/a Quakbot
2023-05-13Cguv.jsjs 2d7e58be70b5b3c1d79a86cc8921d2026816c9826f2997f2c6ef38013a1dbd52n/a Quakbot
2023-05-13Nxcx.jsjs d3420209f9a74b84b26694b703692691a0ca4e5272e03f26f2e50c73c4821dd6n/a 
2023-05-13Qdcinlo.jsjs de33a77e4ad2036c4cb0223f1297da43fc17fa014e644349bf1147b56686e2e3n/a Quakbot
2023-05-13Rjzxbye.jsjs 40728bb5e19d7882317b66331bba937c6bddbf87765027e0bbbd836dee4fc33cn/a Quakbot
2023-05-13Phgvb.jsjs 273990c6010780d0b12960ba7c6b670fc153a410426d8adfbf9435ae5f2322f7n/a Quakbot
2023-05-13Khorgq.jsjs f04cd3b7359f799430be8b7bdc06ed594a530fdfd125562f19dc6618245090adn/a Quakbot
2023-05-13Fuplts.jsjs f7450b48c81f68c36762c2dd5ee89415a5086a6ccaee537c397512b95c710138n/a Quakbot
2023-05-13Bxgfc.jsjs 13efcb7c27543ade85a2029223307fc4940f1c610ee570e7218ac9bf496f7bc8n/a Quakbot
2023-05-13Ojvbl.jsjs 2500a93bc16ce38cbb18b87274555a7997bc1cbc4d41e1ca75ba241cb7cea0e0n/a Quakbot
2023-05-13Gnmq.jsjs 87a522c33376ff2fb4743e36c4a163c5e7017f638b8bc19a37ac921ec15faba7n/a Quakbot
2023-05-13Ylhex.jsjs 048e22b934a8e380fd43728987971942f0cf69020142bf3161542664d5b9fb79n/a Quakbot
2023-05-12Vcrbocjd.jsjs 028992cfddfd8f7c7ef6d1ef26ff01d4e1b12d9bbec367276b21703cb2528234n/a Quakbot
2023-05-12Uezqi.jsjs e94274e2a4bd04d9541c3cbb45fce2c96aba5caa4e4e0acd24c9a67cbd0dae52n/a Quakbot
2023-05-12Ruyjxoq.jsjs 4ef881612d5e85f00d43a58907e71f064f02bed42b8c0e3a2bf7686183620273n/a Quakbot
2023-05-12Zfkybvw.jsjs 88fdf09ceac955955ffb88a329d3b9b5310f217e716a26ee86cfdd793a25b26an/a Quakbot
2023-05-12Xyzk.jsjs 9ec48771566d9eaec23093c32dcf16e2e93a0afa22aa0a6dd0f7eaab0c421596n/a Quakbot
2023-05-12Jtssjkya.jsjs 30ca635e2e17271540394f351c43a46b14647ef092bfb6533daa743296b7e86cn/a Quakbot
2023-05-12Jdtzlcf.jsjs a59e444967d590518183b7786a3260907fdb852f672fad136c0942447db28a44n/a Quakbot
2023-05-12Jcntwo.jsjs c123d09b951d09227399ae4c493653219ea7d4f380d87e2af8b84b17f60cf4f6n/a 
2023-05-12Iyqyfdni.jsjs bf6a9b7e0a288a8bd36abf1b28ce3d796da01f93df11cda259048ef04173f422n/a 
2023-05-12Ydioagca.jsjs 3f7a1b018d8b4f7ae18f60153946f3a1be0e9cb4cea7daafc80bf2c6400c1392n/a Quakbot
2023-05-12Hbpfgle.jsjs 6c2d06b26be4a76f55b46bbbfd106e97a11890973ec4c63f66e94fa30fc09c61n/a 
2023-05-12Dzyb.jsjs 9b8ff03e31181ba0b0ea8e645d9f377f9b2f73e33465684948c541da6f05a34bn/a Quakbot
2023-05-12Uhilor.jsjs d2ab5e376ce0ac9711fcfe6ffb65952c06acb9434be7acfc6d3b4368c6814c60n/a Quakbot
2023-05-12Mxjvfdi.jsjs 0e2e7575639513d7ab51c210b085664aa5ee805aa85e00253ae5b0c5a7811cban/a Quakbot
2023-05-11Wyaisa.jsjs 0665a44a6ffca4d12adb521e5192842180b1f047078eaea288bc1f920f84aab8n/a Quakbot
2023-05-11Abajfy.jsjs a572f37d23fa304c0690d1d2c76c35ece3687e949caa0a64117d34b102fcbe04n/a Quakbot
2023-05-11Hxjfc.jsjs 5064aaebe77a52d68858c9e382a93c7a00f876c2c1dbee8c55826f9fe41b89c1n/a Quakbot
2023-05-11Qcilm.jsjs 1a73f0d9e7f5d9e6521a261790fc279d2387ce919e601232230c89e75a0ec3e7n/a Quakbot
2023-05-11Mnsmlnra.jsjs ad756eb56f7658a353b3480f54939dd6beb2beaedee95e19cb096a7974370c1bn/a Quakbot
2023-05-11Qaiftfo.jsjs 0f6ea5c6a75a4cbe9f42b78a405357e7cb84b275328164f81982ebe7b1f37825n/a Quakbot
2023-05-11Mxecbaot.jsjs 6389187fa95ec64b9382f2c45fe8aadb098de8656cb4c091621bd59b6b180031n/a Quakbot
2023-05-11Dnnzt.jsjs 9bdd77fe6500daa967f5436e5163f1b80279640f8cd69bf7b0fdd52b487097fbn/a Quakbot