URLhaus Database

You are currently viewing the URLhaus database entry for https://realtouchparis.com/um/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2632489
URL: https://realtouchparis.com/um/?1
URL Status:Offline
Host: realtouchparis.com
Date added:2023-05-15 14:49:07 UTC
Last online:2023-05-17 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 01:20:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 7 hours, 8 minutes Poor (down since 2023-05-17 21:59:03 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-17Dxfk.jsjs bbb3857a4a55979cb62365c0f64de4c52d6dfb99575872792f1875a6b7d5afd9n/a Quakbot
2023-05-17Kukrsdz.jsjs 973858251132d0779245a2e9dd301914a73702dadb9512759bce343a0fa1cb23n/a Quakbot
2023-05-17Jwvklsly.jsjs 0c7ba195ded6d8e316021ca662000aef82b48c95dffdd60c2ea37f1849c555b6n/a Quakbot
2023-05-17Dzhgjoby.jsjs 90fa0f56e8df4147606c0590d9bf8794253f48339dcf3295c0bd6d7b2dd0664an/a Quakbot
2023-05-17Pzus.jsjs d72be2d3e9fcadaa237d2573ff95eacd51e973b70514465c8d57e7cd957769b2n/a Quakbot
2023-05-17Lmtdfku.jsjs 86f5d7a827c67f2c62e9e714212d133f66dc43c2885073f58d29a595a726db4en/a 
2023-05-17Aepkqomg.jsjs 042918d08ef08a4688c21c91ef91f6ca1b005b6f5cfdd40932283ad12848eb34n/a 
2023-05-17Yqnfqq.jsjs 4dbabc158f7b42d6bff67609276950decd28bf66b547aae0db0dd12452dd610bn/a Quakbot
2023-05-17Ljwoy.jsjs 6eaf63bb93650deca746dc5d8900981b833e62bf28b977e70392da7ae18de7f7n/a Quakbot
2023-05-17Zkcldgb.jsjs a6c30d9232769bea625ee2d8036332a756e4eb325abc068d9e000abebde2d345n/a Quakbot
2023-05-16Sdblcsw.jsjs 1af08b2dee173e9137c973a7f7d11c58e29acffbe1fd788a2c87c0cc4e45e3abn/a Quakbot
2023-05-16Qendhgye.jsjs 0c477ff2abecb67c9afe11685ebfb571d8b556656770ba72c159c7e998ccac8an/a Quakbot
2023-05-16Occji.jsjs d365dfa97cee4ba7deb193f4feb5c3c4df1cde44c2861551f177590ae3eab1b2n/a Quakbot
2023-05-16Wdkrvs.jsjs 63a22f11698b77e1236c179d721edbba6294ad60b8e4e9a9cbb6601ff45be9e0n/a 
2023-05-16Ecycmocn.jsjs 96a8b38c888b33c5b8159b0907f76fbc168cacd1c389bd277d90cc9f4f252377n/a Quakbot
2023-05-16Maoeltk.jsjs 37c8d47d91233bcc474627015722567fd4999f08577669e63bc6cd9e1e09e738n/a Quakbot
2023-05-16Nngxtud.jsjs 66f0e3e17340b4163f29c0cac2c76f57d7a3697be8083d894699cf1386a96b13n/a 
2023-05-16Jrfzbpzh.jsjs ffe7263fd8125c0134377939ac70f3c6cc2a22fad91ea9730328702e8de40e67n/a Quakbot
2023-05-16Wqbcgjjd.jsjs 675ecb847faf81017b06beee97b59c9b73995d2b4aeb91bd4645557366d130afn/a Quakbot
2023-05-16Wpxx.jsjs b21b17facf12d91087fd753e3d9304406c9b1d863e911777e9eb44448b80ca30n/a 
2023-05-16Cvsnl.jsjs 403393732caa284dde1faa15a5cf86b3c62cee1427bf0289d7345d6347f4ea38n/a Quakbot
2023-05-16Fhfhstj.jsjs c95e7f82e7097418f425a98c08d3321c147a24bac81b746d72a8cb9c044d213cn/a Quakbot
2023-05-15Quoybjyj.jsjs 4370513fc1a96382c8d0d4c987d635ce696dd3443bdee85cc06a7980893605b0n/a Quakbot
2023-05-15Vqsb.jsjs b77a7fbcd21428eeaebc2f3d65cb6d3740f5008598f02104c68b4b4961b2177cn/a 
2023-05-15Hqyyl.jsjs 125da995ca5304c6f62e75aac31d4676485157602138339d81aaf7ebf061c62an/a Quakbot
2023-05-15Chovskd.jsjs 6d0f9f3e7f0ff1d00fa4fbfad0129973700f19397a8e52c1aacbf11d3e667154n/a Quakbot
2023-05-15Iwye.jsjs c5a88d723949175107c8db9e3ab8ac918b06b81089f10aec8d7c658e1f0dceffn/a Quakbot
2023-05-15Zjptjsf.jsjs f2a5cdff1bfed59c66492f2e19aaefb78fbc5230ce25f15cd054a9edcc37a7a1n/a Quakbot