URLhaus Database

You are currently viewing the URLhaus database entry for https://spmmedicare.com/us/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633029
URL: https://spmmedicare.com/us/?1
URL Status:Offline
Host: spmmedicare.com
Date added:2023-05-15 17:22:16 UTC
Last online:2023-05-17 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100115979 created on 2023-05-15 17:23:06 UTC)
Takedown time:2 days, 4 hours, 32 minutes Poor (down since 2023-05-17 21:55:49 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-17Jvipqx.jsjs 32710b418e9ddc449d0548590b62ac23975ad6efba53cc55cb1551326e182cb9Virustotal results 30.36% Quakbot
2023-05-17Zopug.jsjs c2c29ea19d16a1a70e365c2161d223994c0610958fe527bfcb605ed47c4a4d44Virustotal results 32.20% Quakbot
2023-05-17Aqqevrx.jsjs 60483947f59c4a843833ac5302fae111fb318dafe639770153154f7e01c2afa9n/a 
2023-05-17Zmeqsg.jsjs 6bb7a104fe821f46f0853eb826d375aefd2c29fca71738cc3494e5cd9ad1c40dn/a Quakbot
2023-05-17Nqmqm.jsjs 0107042269a76269dd71d3dc19e72a1759d421cbf33b9758b94f08c93f0989e6n/a 
2023-05-17Xlhof.jsjs d2338cd0376171b31bef79e7bc05e3954d3c61c6f23184804a1a1110dafa3d36n/a 
2023-05-17Fkpuqvjb.jsjs db61cbcda1a1f36c6355c68cdc10257419ac89a442c6d414de7992c260d233a3n/a Quakbot
2023-05-17Uuwdxzk.jsjs 6ac58b5ab4723cd3f489c655f6363ef9c12273ecb718b581bf5de829d82d65a1n/a Quakbot
2023-05-17Uwsvj.jsjs 0c39ef4d975bb585d89d6d4fee9142d98bfd6ea095d6f92288482b8af837e34fn/a Quakbot
2023-05-17Jfzxevts.jsjs 633eb0b07835479765ca23af28642fe56441a010e3fed8fede385aec902e0d85n/a Quakbot
2023-05-17Mhwpet.jsjs 8d1d509f36c033781420f7e70fe6c320a55596e3e235ced2ba8fd9d94140f1f3n/a 
2023-05-16Zvoyaoml.jsjs 6099b7432719d737e8881b59a84794bc2409fef062214d32a3a86d1c58de3a2fn/a Quakbot
2023-05-16Ahvuo.jsjs 31da32577565655867e39b1d5e12f33fdd509c0ff5db476f3c5c3f30814415c7n/a Quakbot
2023-05-16Ufpz.jsjs e30977008a97442bc507e7fe28f1eaa855bb4ad973da71e3d6a5cf5dbcde2338n/a Quakbot
2023-05-16Ffhskg.jsjs 43bc4ca7a0a20b3c3be441b04ff5c97414201ec529235a70ac0032feecd649fcn/a Quakbot
2023-05-16Hsqdjyx.jsjs 9fd8397738ee03f93612c186596b64596f9e240d4205184a0b40fe1fb25c1e45n/a 
2023-05-16Hdubr.jsjs 14714e4d14cceea2be563c01463757070274e3bdcdf40f40ce0f384dd8005345n/a Quakbot
2023-05-16Vqksaio.jsjs ab791426cc4222436d987f97e8d2f4e4fe724784232892c46e2840bb6466ccedn/a 
2023-05-16Hqrcyjtn.jsjs 6c1e9bdd6461e7648b4e233047627a25a12ed08e16d5f53112132e2b252a84ddn/a 
2023-05-16Hzqu.jsjs a3f829b108fb249feabf803e3b63b77e0cc1d72dc8b1c1eb9052ba8766ae1888n/a Quakbot
2023-05-16Rnsaxd.jsjs ebe1bd8ef30afc5724ad94bd5f754af6d39d395556f489e1feffc52cf307b3c5n/a Quakbot
2023-05-16Qwhqczuy.jsjs 002827648e131cd4917b6f756c2665645e4ef6562201ebf72839dccf5d900e8dn/a Quakbot
2023-05-16Gttteau.jsjs 7dc34b5f9331f2b50570f6eca8f495f9090a3cf7870531eb9e045c956ea365fen/a 
2023-05-16Itugxgzx.jsjs ad6a468cd85c71d67e1bdd94e57d88b89e1e39b60d06c57a5939e203bbd33c73n/a 
2023-05-16Xjyeu.jsjs 6afaf72f682ec873e69ebaf59d04ffa8205fbec52990856f2076b9624efe6e9en/a Quakbot
2023-05-16Abthwn.jsjs a98c25ad22062b833d0caa7965dbd7c147f778b9152b628773552c2d6756c3b8n/a Quakbot
2023-05-15Tkjhq.jsjs a410b5c06ed3ae7726b2e8bc753227c289ce2a74c28ab54a13c50ebb950334c5n/a Quakbot
2023-05-15Gospzy.jsjs e6a1ade066674157841c3ee63dbca5a65daa508ba1ac46e02b4323ff707394ecn/a Quakbot
2023-05-15Qsxv.jsjs e8b3afb233d1ad49b625d432676d3afafc93d3c8b47e1acd9dc983ba7b22adf8n/a Quakbot
2023-05-15Fcklcvy.jsjs 4b9125a43cafe56ee817460c1866a21e1fe71181feada93a2e640d25c4fc5adbn/a 
2023-05-15Vhfirf.jsjs 0a984adc48912d8ec2c06a2c373fc2364a95b1432d58b285d42bb3b32cf786d9n/a Quakbot