URLhaus Database

You are currently viewing the URLhaus database entry for https://gprproperty.com/ttau/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2630063
URL: https://gprproperty.com/ttau/
URL Status:Offline
Host: gprproperty.com
Date added:2023-05-11 16:31:12 UTC
Last online:2023-05-14 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-11 16:32:34 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 8 hours, 0 minutes Poor (down since 2023-05-14 00:33:27 UTC)
Tags:BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-13Latcga.jsjs 8eb9c7cca4850ffcb494d4c0e8a951961a7585f3b6f889c9c60459ff620fa910n/a 
2023-05-13Uldb.jsjs 5368cd30d456065821f0a587acc6d2ad028bfcb596618920f18d21b5d1f77b70n/a 
2023-05-13Gezeom.jsjs 4c5c19a56534c724e75b0edf4ab4ad9a461ebedd76613518e9a3adb4f2c8e4c1n/a Quakbot
2023-05-13Dlahfdjo.jsjs de01c08f224a94cb3ec80d9e32763052cb5599043c5f10fff11164552b729ad0n/a Quakbot
2023-05-13Modfg.jsjs e8b9dfe8a53642d349d9ed609d25c080fe72c201ebbca59007d3c55c723661e6n/a Quakbot
2023-05-13Gpeptmi.jsjs 1ad802e8ea66ac4c8a52cf489d17143c8126faec41819630e3fb144bd0eb571en/a 
2023-05-13Adviti.jsjs d32f7ba18e3ad0c7260c8304d558ff19bcfe7a0515fe2c20ee2c92a9e8e60943n/a Quakbot
2023-05-13Aovw.jsjs e1071b985dc4c3d76c307e80af7935f995aad40af9d84526d7c57080c8a9f94bn/a Quakbot
2023-05-12Qvadvubz.jsjs 8bf520ba310c849af6906d193f950f47480ace043111fd6dd476b624f1d34298n/a Quakbot
2023-05-12Xxtkqw.jsjs 28bb05dbe86417d8f9f943b72c6d3483bd436b5e63701121620b741fd36c5737n/a Quakbot
2023-05-12Rwjw.jsjs f476b1759337fc090f42fb56d572e15a23d0ae557e954440b86fc722e7ea97bbn/a 
2023-05-12Bmxmqokr.jsjs ce280f4c77cf56df5a5c07668c0c1a82cf705cea75a52a6cac5cced6edd9818an/a Quakbot
2023-05-12Xwfgo.jsjs b2aa4ecb643c8318d8f1209ee8cd90329f48985ddbc54a475545979df4d68a73n/a Quakbot
2023-05-12Blvqlgs.jsjs a6675b3829fcd6827d00a05f78ce171eb5800f6253cf057d59451176259caeb3n/a Quakbot
2023-05-12Polkbx.jsjs 7b05e9c5e34eead9d44bbc1402ce9603db7b45a5ddfb0de77e7aec0e7d4e8f39n/a Quakbot
2023-05-11Ngkbg.jsjs a8d4e19e6efd997b679e902988d80f0577a15b596025a9aacc36f46bd2cf102en/a Quakbot
2023-05-11Yndghjw.jsjs 87e891d41ae8f419b53cb78ccde69c6d772c8a332ad6804358c1f620c0943dc9n/a Quakbot