URLhaus Database

You are currently viewing the URLhaus database entry for https://batsamco.com/un/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2632753
URL: https://batsamco.com/un/?1
URL Status:Offline
Host: batsamco.com
Date added:2023-05-15 15:15:09 UTC
Last online:2023-05-17 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-15 15:18:47 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 6 hours, 9 minutes Poor (down since 2023-05-17 21:28:28 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-17Ovuzhx.jsjs 0769e73bc4ebc2ee5fdfb2e6d02b6a282085b48c709104d96e856380e8e4ecfdn/a Quakbot
2023-05-17Vqof.jsjs b76a46e9b0db483e342c390f25663222fee2e67cb7670205636c7ee748850b86n/a Quakbot
2023-05-17Rdimxspw.jsjs c419bc2833e48f8f26166ef911d3915be8fd0619ac6a0e0638813a4404df6979Virustotal results 25.42% 
2023-05-17Mlyy.jsjs 426babf013bd614f1197dea8df2fac24ddfb79398b8310b46631885ec666eb54n/a Quakbot
2023-05-17Jlsanvi.jsjs 4ade6f7d7cfcd03dbffdfe401ed93fa601500252c858fa6010e54b0587fa0249n/a Quakbot
2023-05-17Qwtclq.jsjs 8772156f90eaf1afea7ef8aede91a10a14f6ab0bbfc0cb8629917994af09f843n/a Quakbot
2023-05-17Jvzf.jsjs b4aacdff68089fe9ef39db86e0a9f3025b60fecc54800ebec33c9c9038288321n/a Quakbot
2023-05-17Lzvw.jsjs c376b9a24b52ba5b7b5552383f45f7909b99fdf1c71310c230b294661ea64974n/a 
2023-05-17Chsih.jsjs ff5332b0eda4c302e602c818c9f56c53a138a0824fce991d19ef0cd054ec5c09n/a Quakbot
2023-05-17Szbi.jsjs 709766f9e2680d1080a394fa085358c6db4e3170af0d1c26f34e67832ea9fd29n/a Quakbot
2023-05-17Dkywkos.jsjs f849f53e4470647b9bffa2d82f437a888e499da3ed999594775d51c7cbb55c09n/a Quakbot
2023-05-17Kqgudcxe.jsjs 1c3bb0fbf518dc659f6d832e5d0fc21c739d04b6fadc8edac3f2f9fb305af1ebn/a Quakbot
2023-05-17Pwab.jsjs 093947270e191374909f6709ea54d96297807255a4e2b7483ed9b18fbd623324n/a Quakbot
2023-05-16Mpmxzi.jsjs 26a0c64084a25dcdf6df64234578829eb6dac96ea3319c2d4ffb5a2878bf7032n/a Quakbot
2023-05-16Ecbcozno.jsjs 3b3eb6da32bb77f5281f25324ce8d7f67b414068f4682e1a910894c202b1b742n/a Quakbot
2023-05-16Dczm.jsjs 8902b3db6673c926b50e7ffb41bd57de01aef3c322b34f8bc466236f0ed19dbdn/a 
2023-05-16Yofmdge.jsjs ee8e6e11a472b7bbad23192cc483d99d966e87a570d4d5094f2f9ecce44fd7c8n/a Quakbot
2023-05-16Fqnwhl.jsjs 97eea960777096ea9f82e9ddad94cfdc1ccf9bd3885c2f7746416e98e5b36f9bn/a Quakbot
2023-05-16Rafacc.jsjs efffc36ff54f482ee81331c236bbcd0689a004ff10a7e7727b791337b104e2b1n/a 
2023-05-16Bywrj.jsjs ef52587358097ef770eeeaaa7afa2a63493f64df2b79d016643f5bbc71786291n/a Quakbot
2023-05-16Kugxae.jsjs 6ad1b382e9a4731a9d08560f410387ecb16aec7314415e563d5f6b1aa0958304n/a Quakbot
2023-05-16Aewimjdc.jsjs dcb541ab85370a9ac8b4afbc443051795ca13776aed3350210a0fe51c745e872n/a Quakbot
2023-05-16Hflkv.jsjs ddac13ad3747734bd942401ea4a4d834cca9eb10c9702a948e879d946b86ddffn/a Quakbot
2023-05-16Jcogg.jsjs f61cd07c68b9f240b1e3c3c71564e63f3f8ef64f4ec298f55bf34d56cb5492a4n/a 
2023-05-16Otjpi.jsjs 1bf8946e1f8ee6fd8ce99e10fb317b94306ce249074b50d9d5d124ce59aefc62n/a Quakbot
2023-05-16Htwmoak.jsjs 8af1e119e5b06d56a8806fc2f85e91579d5f749dca2eeb41f6a0bb8ed26e5c0fn/a Quakbot
2023-05-15Eunwnu.jsjs 8657fcd3096e728a1c632cd8a08e17868bc7a11d101e63e73af4ecdd727b8e13n/a Quakbot
2023-05-15Gnlhu.jsjs 8d638f3e8a9197410d68df0ea574350304cbc5a85915e5f68b7ba4fa41c75492n/a Quakbot
2023-05-15Dgipvymt.jsjs 12471b96f5f2255a3d28aafbe0a06e2db95c3fcfa59b2745b6f6b0691477c56fn/a Quakbot
2023-05-15Muhobu.jsjs ccd838684e88f6207db75f651aa292d901f08638606bdccec87ff20edd7b9c52n/a Quakbot
2023-05-15Ljnnxqgv.jsjs 738ea9b75c2d9ef4c8b579fa90095fec1f8e5085110a827b4dde371a68697935n/a Quakbot
2023-05-15Oipygi.jsjs 1fe836a31b3a6892d9cf15adfc1ef75a42807e73036092a77fedf48d81a74617n/a Quakbot