URLhaus Database

You are currently viewing the URLhaus database entry for https://kzpott.com/iis/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2632677
URL: https://kzpott.com/iis/?1
URL Status:Offline
Host: kzpott.com
Date added:2023-05-15 15:14:47 UTC
Last online:2023-05-17 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-15 15:17:49 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 6 hours, 54 minutes Poor (down since 2023-05-17 22:12:43 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-17Ufek.jsjs f65cfd45df99f110dd5e24acdcb4a032a333c2d5f289d2867feb0d7fc6aa1960n/a Quakbot
2023-05-17Mlygi.jsjs 4a5bb0d1af42aabd643a23c518cbc77c4a2931fab8d180bbad1c0ea815f5954an/a Quakbot
2023-05-17Ahvshi.jsjs a64cebdd853596ce95beeb112b9dfab6eab26ff09b77eaad1c909cb1b6cff48an/a Quakbot
2023-05-17Umvis.jsjs f37d3c915b896922eed07327ecc8b944fcab1445d20c02c26c5aab8d91473b45n/aQuakbot
2023-05-17Jxkqzhcc.jsjs 3f981a1967089e05af05885173620b3933551cec4a09409c5472958389e98ee7n/a Quakbot
2023-05-17Qrqkii.jsjs bafe320776bc2529c835ce971b6865063820cfb46ae15852c7bad4e54c9bb47dn/a Quakbot
2023-05-17Beay.jsjs 7797932797f41de1c92c1de7261ccf2ebbf77d0a22c000f66e628ac0d4232af3n/a Quakbot
2023-05-17Aehdexw.jsjs c51c0f4ad4a1daedd37faa64ee13626367bb85351c43f75d5fb2574906e8d72cn/a Quakbot
2023-05-17Qetcdjl.jsjs b7bb9b67e54b717680a9d2f0d17f2fcc309e654750ee0337c750760cce043404n/a Quakbot
2023-05-17Lyzn.jsjs 67358af4dc6bb21fdaf08da3622bf6748a4e667c4d3742d1078dabfa048cbcfan/a Quakbot
2023-05-17Dqgye.jsjs 043109bc560ffd09e43d8663db554bb676f94bd623a3d35e84b8bfbbd2b82ee7n/a Quakbot
2023-05-16Kbbw.jsjs b85f601c37cc81a12cfdd247856c44bb22c89c0a9275f35557d7a0682522a4can/a 
2023-05-16Tpatrxs.jsjs c15ab776c1d8e8d80c43d348451e3e9049c979687a8aaa7e5b8dd1038da9050en/a Quakbot
2023-05-16Fwllomht.jsjs 591712e8f5b134e1a3660b1833aeba3d7e78f50672170670f682a8c081f1897en/a Quakbot
2023-05-16Qkbcroy.jsjs 70d1288a607fd1f74ad5f72746ad1bdfdbc40e16666946f6dd645607bd721141n/a Quakbot
2023-05-16Ipzttlmg.jsjs 1c7bdc975811d20c41726d0dfa9b1fc4ec1d01f8f8cfec22a93960edc73e1132n/a Quakbot
2023-05-16Okxviod.jsjs cfbe0c18e1fab9acc97b891f292a495653e895ca6b797018b77aabab845da78fn/a Quakbot
2023-05-16Kixq.jsjs 0b07d53e6d17188c476273992e6d269d70530ed22fa9abd7d94a365e507f82b1n/a Quakbot
2023-05-16Bnvbxmrr.jsjs d0f5c5549d34d673c4f0a37cb2e0b8375377051455322bb8d6d9c149d2df7d96n/a Quakbot
2023-05-16Jybczx.jsjs c30a10e18d0b7b4f5a5e122fee2a3568dc733fdb3724ed664553ac8ff37bd6fcn/a 
2023-05-16Ygtljs.jsjs fd21cdd073b4410aab16febbb0418351c19ba26ee177c3c1d7f81a4749d2a3a0n/a Quakbot
2023-05-16Xrsdd.jsjs 9ae2618021eddb2f4d2d0d120ec5213664faa167fe4dc494b94e3f13d69f2dbcn/a Quakbot
2023-05-16Nnjjj.jsjs e06e72a4fe029d9c6e2c478aec75dbfdb6a38dd2f2bb245205bd7ef5c27d5244n/a 
2023-05-15Slrgdd.jsjs 6bab7a20051b3ed99b21e731970eb8ffd1854f2d52317bf363c453a562eba655n/a Quakbot
2023-05-15Lussajf.jsjs c6f632a8acf3a46836dc173731773d971bc8de0adfdf6ef577c852354016b3can/a Quakbot
2023-05-15Qtmzd.jsjs 878dc8314805491aae8003158559d658faa0fa4661871b1c0ff2f6f82153299fn/a 
2023-05-15Flgqmcu.jsjs b0f26d86be5ffc3e57c0e806e5562b66934943463648541bb4d421025e1420b7n/a Quakbot