URLhaus Database

You are currently viewing the URLhaus database entry for https://fansitemanagement.com/mrt/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2632562
URL: https://fansitemanagement.com/mrt/?1
URL Status:Offline
Host: fansitemanagement.com
Date added:2023-05-15 15:14:18 UTC
Last online:2023-05-16 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-15 15:16:07 UTC to netops{at}singlehop[dot]com)
Takedown time:1 day, 1 hours, 3 minutes Poor (down since 2023-05-16 16:19:50 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-16Gcdbtzm.jsjs 64bea5627f0f35e604b19640ab70e05c4779a4d73dec7ac220bf2e19695094ebn/a Quakbot
2023-05-16Utkrbir.jsjs 896526a5c349fe4a17294c68916e183e1ed86ee591a7d4616bd32c0aedd5f941n/a Quakbot
2023-05-16Rbsp.jsjs d18919155b18a6b2dd3cd02f781f1f0b62c1efbbf4039f56a877b517012ce42bn/a Quakbot
2023-05-16Awiuogn.jsjs f270270436e4fe004d788f4e61fbbcc37440ee530955a95db48ee0cd6ed32155n/a Quakbot
2023-05-16Jiamr.jsjs a32f11695cf1135c53455dfbe223eadfe68f6e8476d662ffc97d6d53d9ff7164n/a Quakbot
2023-05-16Fcuhtnx.jsjs e9d6d3ef293806048504c2f078fb9b7b4c17214e5b3b0f17e3f09549db61169cn/a Quakbot
2023-05-16Fzhv.jsjs 376f7ef66432f9dc8e41bfda5d2800ab57df2587cfd5ef63c6c0ba30dcf9cffdn/a 
2023-05-16Nnsa.jsjs 31f4ecca0ed2a5195ce06297bf5626874139e69e78a9c316ec975490f7946e83n/a Quakbot
2023-05-16Nqpb.jsjs f97eff2674ffe6809917ebf44c7bee1225ecba6b12d958c22834dd03b326f784n/a Quakbot
2023-05-16Nubyno.jsjs 2932d76a70f02dbd02bf0decdd538272a00d8db5c066ed96f36cbfd121585b12n/a Quakbot
2023-05-15Iqjl.jsjs f7c0c168431d80f11e6bff6f842b3fbb09042253a555a9f21d3ea64ed95f8fean/a Quakbot
2023-05-15Evkwyzh.jsjs ab39cbfea6b7a16d610124eb7544c6f9856096dd8d5e3015ad42c48454119eben/a Quakbot
2023-05-15Hxjtm.jsjs b35da21cf7a71ed54ee863250097b5c663cd9e6a7ed175b68ac81bb03c209492n/a Quakbot
2023-05-15Ugyzpv.jsjs 58b865c0b9956224c990a0f51654fe54af7147c0618221d988e31a4e2397bc33n/a Quakbot
2023-05-15Ckvfxw.jsjs fae9655605d1ac8982efb565149400c9075cea87d0bbdc9188ef3b689b424a4an/a Quakbot
2023-05-15Qxvbkx.jsjs 74ff82a5589635be7c5b1f6b186ac67e2d0555e8be0704c0089ac24dd2f2ee76n/a Quakbot