URLhaus Database

You are currently viewing the URLhaus database entry for https://balgocburada.com/oidr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2630335
URL: https://balgocburada.com/oidr/
URL Status:Offline
Host: balgocburada.com
Date added:2023-05-12 02:27:13 UTC
Last online:2023-05-13 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Myrtus0x0
Abuse complaint sent (?): Yes (2023-05-12 02:28:11 UTC to abuse{at}ni[dot]net[dot]tr)
Takedown time:1 day, 19 hours, 53 minutes Poor (down since 2023-05-13 22:21:16 UTC)
Tags:Qbot BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-13Rolial.jsjs 213c7caaa000c8a47b696ba3341e35ad1155f3be90c1cbc885211de2721138ccn/a Quakbot
2023-05-13Krfhunkz.jsjs 2110d53deaf29d0eac521c01cd2d4495b9fff20fd5a83f1501bf23897d89f61dn/a Quakbot
2023-05-13Mdaquzm.jsjs e188cf6acb1aa8024cb7e244436289b4cb20ba81fc61d53a5e54b43e329b3093n/a Quakbot
2023-05-13Wrbbps.jsjs 806f77e8c46eab1cf39cd363d227773600c9b3a2ccf4a23c1a2dd158b8261444n/a 
2023-05-13Ltju.jsjs 9464facf972bf51bba4cfd2b8f70c51fb3694a1779a6af3b6c1ce43c7457d789n/a Quakbot
2023-05-13Zuaeniu.jsjs d7cc6b0b08763a1833af08835792019b81be9dc93b4c8abb2c51943754488965n/a 
2023-05-13Spzwv.jsjs 44759d8c4763c8ca432b707bbf8ea8cbb2117dba08a23dcdcbd155096342bcedn/a Quakbot
2023-05-13Woxxrnac.jsjs 0edd917d9201095f5fa97a92269bbe27de31eb32bb0482ab99d19ef8ffda3a32n/a Quakbot
2023-05-13Phrf.jsjs 9e30f8f684aec2c865137ddc1063fd4e7084ae1f8b90ee361ebf2253eaf3ba04n/a Quakbot
2023-05-13Tyiqz.jsjs 1d18ba49efd6eefc302f0151479f69200c4dd0c4adc7428cda5b5efe0d485f7bn/a Quakbot
2023-05-13Xvvucpd.jsjs b8657bfdce398cde172324c5cf112eb27ff1eea0b3e3aacbd22823d929b34b4fn/a Quakbot
2023-05-13Wfysl.jsjs 8b737753cd743097540cc6f16867625789e61054a028b3ac72ff851d6a896536n/a Quakbot
2023-05-13Lidlthxv.jsjs c28334dbc8d9577b006754f65605d77f842df54342352e98d76547f02566deb7n/a Quakbot
2023-05-12Bqaca.jsjs c8f897eaad8fb335f2ca43cd20f199338a0d978c658fb95e4075b7dbcf3e4577n/a Quakbot
2023-05-12Edpsttpw.jsjs da9638354ddd6defdf8e46dccf6044e9f8b45fae7145844a9a924a65c3f0ef4cn/a Quakbot
2023-05-12Ealwrfop.jsjs 80b902b9c96968ee3f15cc7d16fe3a741dba7d435a4e8ce524fb97346b15457an/a Quakbot
2023-05-12Lbdlbwfb.jsjs 17921839e6d478281a0641d68d23a35ea9bafb211f5d89cd8c4ada8131daf74cn/a Quakbot
2023-05-12Qzxbk.jsjs 0fe946ac3f1af73c2bc0c97f0fa3a45f9161206a0222eaa67d14bcef38998573n/a Quakbot
2023-05-12Vkgtza.jsjs bcf4d8841cb89660eb73563619612d570b5376887e8af14336af4d0a1cb5524bn/a Quakbot
2023-05-12Mmyyttmv.jsjs 9594192e3fc28091d80144f5ed162cffb2d40c4df5cdb8ffd3ef760683e83eb1n/a 
2023-05-12Mlfztt.jsjs 5d3cd22ecc08aa5f9a5b85a820b613a19457efa5f301a4c629e2904768faf045n/a Quakbot
2023-05-12Oowotpt.jsjs d7c0d8007ec4353914f541f152eefb4b82d7f4dc86f079c356cc44c904c30081n/a Quakbot
2023-05-12Txsbfe.jsjs 394037f59eef42d07f23931ce75c06a0e05dbecd6391730363477527b593161dn/a Quakbot
2023-05-12Oqxqlso.jsjs df52efb511f46fc961a519d141154cbe664380769a12b920a91b9a464140cc8fn/a 
2023-05-12Rjgfnxw.jsjs f6f8f618f1660b04ae32ebd7fbf4e41a4ff199f6e750a9297687ec78558447bdn/a Quakbot
2023-05-12Hola.jsjs a36d0433ed8ba932a8c1271a356c992a3612f759d8b7b0733a3f921d29f0cacdn/a Quakbot