URLhaus Database

You are currently viewing the URLhaus database entry for https://klimabilgisi.com/mnrm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2629841
URL: https://klimabilgisi.com/mnrm/
URL Status:Offline
Host: klimabilgisi.com
Date added:2023-05-11 11:58:47 UTC
Last online:2023-05-13 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-11 12:01:54 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 10 hours, 4 minutes Poor (down since 2023-05-13 22:06:40 UTC)
Tags:BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-13Qplgysf.jsjs 6a99e4aa20ff84c2a352bebbd88ba9140ca6620cbfdfeded8d70435cd1adb617n/a Quakbot
2023-05-13Igpwaidv.jsjs 18ebcd582a15459a5f2138939964097d2bd4e3abe698205a526a182f6aca6fb3n/a Quakbot
2023-05-13Uovimkxp.jsjs e2fcc2cdbf44041563f333df7437b7ed9682ab788b7fa5bfa967c76e754c0579n/a Quakbot
2023-05-13Tsyf.jsjs 9ef67b088c3c36dad1033fcc98fbeb6a422d2127a0e31a6d8612077c9185612fn/a Quakbot
2023-05-13Ndjoixv.jsjs 5ce1ea98cde8f443622e36669c7e5d4dfe103f76604cfd03d3c7e473a3250e79n/a Quakbot
2023-05-13Tcgexqiv.jsjs 149c3317b4b4317d48fdaeceaff2b50b070d393611058b8e66977b4c874c7e50n/a Quakbot
2023-05-13Xazv.jsjs 348bf8d9217acddbfc04a1f885d1404dbe1bc48b8a8d0f40f33e45e50bcba501n/a Quakbot
2023-05-13Uksu.jsjs 42dddc3565ada59ff136df58af2d1d996e32af2224b2450c2a26088e7baa5c9fn/a 
2023-05-13Qpnub.jsjs 561c5a1fd7ddfc845646ad9f64c3b29eef93df62f68e081d73646bdf2feaf6c5n/a Quakbot
2023-05-13Mprscdyt.jsjs d9ad1aef11b7e871ae1fc52f1069931d72f8284db6b8f5d4b6f0e31daf51b9b7n/a Quakbot
2023-05-13Vlgh.jsjs ec24cc32b98dc74d10069230c239d81ab3df429a2fdda80834eb4916a23c6961n/a Quakbot
2023-05-13Nhshzpr.jsjs 55076a991a43e1e8fda6dcc309603125bb6b05bda3a13a498a928f6b3cb7732fn/a Quakbot
2023-05-13Ilbsijt.jsjs 7703c3e3909c3023e64e01ef49d09cfd15bf432136ac4d4adcc4dd730c4453b7n/a Quakbot
2023-05-12Npkfsqk.jsjs 6c5b0f0b4a632573160e21b8fab946d79814ad980547d0507d4c53994e3ea7f6n/a Quakbot
2023-05-12Pmbpubh.jsjs 8d19bb50be4f6ca8a1ee968ea956520dc9dd0926fc835451ee18e369fcf5f389n/a Quakbot
2023-05-12Jikv.jsjs 454fc61766eee6cec79b95816eaf1e7b73c6f31bb2e9722001dd8011e2f080d1n/a Quakbot
2023-05-12Xymn.jsjs 369f8fd27d8a9835bedc515e14419b6a06974f43d774f4b49224ffeabd18ae41n/a Quakbot
2023-05-12Nsdlg.jsjs 8de11d23705c0560a85502953188a25bbc4332102343f0e9879a051beea9e724n/a Quakbot
2023-05-12Jlmlacx.jsjs 439a8865452b52a2fb154e3927b322d9a14d67121d73f006ce784714367cbc43n/a 
2023-05-12Holl.jsjs ad68e0225900d4a0bb8176e58373c879495d96552836a2daf9d91cb9213313f1n/a Quakbot
2023-05-12Svlduflk.jsjs d9c9619280ad207400c025bb82da845ef3601f4544ecf899fb8e866b0a1338dcn/a 
2023-05-12Qdkrdy.jsjs fd36a61db4f1a178a36fbfe78b1220b13145fd4aa63a8de15fa8c4e3e246ebf9n/a Quakbot
2023-05-12Oydmfkq.jsjs 3212b6b47164fe1e8ec9154d60d2fc8309c60841f85d46293e747d3f2eb599aen/a 
2023-05-12Keuidbiy.jsjs 4699698850ca8241c558268f9b5eac17e534761b39080d169f1504214faee584n/a Quakbot
2023-05-12Zezmx.jsjs 65230f4fc6feca1f8bd22e4858bf147c5062b3b3b97edfca1808180b7093a3ebn/a Quakbot
2023-05-12Rxaek.jsjs 8e3af17c4ca0c1fc1b0d0601e368b1976db1bec448c3fbb10e5d7867d12deb34n/a Quakbot
2023-05-12Favomtas.jsjs ce536584f2fe79c94580eb6424e977ce5c33bfee4a580a97b7c6e8640d07185cn/a Quakbot
2023-05-12Vzvn.jsjs 34acfb8e4f2f310c35874b15bbe6ffba9b5b302125205b701b46500f453f9919n/a Quakbot
2023-05-11Mwno.jsjs c59855acc585d1195d1bd9dd1ebe1f9e6a80b64f643f3300f4736a3ecbe7c615n/a Quakbot
2023-05-11Azxgnumz.jsjs 4ba7fa02f7f3297d6a34c045683de0d64bdae451de346e541af54ffdb528957fn/a Quakbot
2023-05-11Talug.jsjs ba54219c667087ede47d96f324141ad91d04a26b575bf2f7708760122b9b91b4n/a Quakbot
2023-05-11Loubwysq.jsjs fe527b9aa7a87f98e8db533639e1ca553e2e417acb9447be4c5b2b272323321dn/a Quakbot
2023-05-11Aiallm.jsjs 12d7fbd1a7ce8c03624e7c59e91ac6d89269e8bb8ff6d3c00fa34743e4e1d1a9n/a Quakbot
2023-05-11Xupo.jsjs 31d352af4ad8893e9ee2268ceebea283995d7b91be2f724e6adb13e71eb9aeb3n/a Quakbot
2023-05-11Nzhsp.jsjs 10d50069a6b3fb4ebd0221fb9ca953810c4c47d415044e282e133c927d7f0843n/a Quakbot