URLhaus Database

You are currently viewing the URLhaus database entry for https://baltimorewatercleanup.com/ru/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633560
URL: https://baltimorewatercleanup.com/ru/?1
URL Status:Offline
Host: baltimorewatercleanup.com
Date added:2023-05-16 11:25:17 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116406 created on 2023-05-16 11:26:04 UTC)
Takedown time:2 days, 9 hours, 45 minutes Poor (down since 2023-05-18 21:11:39 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Metwqr.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Hltkqsl.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Ugsvgczv.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Emunz.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Zmwcudtu.jsjs db59b4bee7e7aac147c463e8fed982b77b3440646771e7e8f73db27a7d8c23cfn/a 
2023-05-18Uxdraq.jsjs 043c810fd7d77672928841fc44891531ce536c6b4cfb9a4e54529c20b36eecd2Virustotal results 30.51% 
2023-05-18Vmjfbnwk.jsjs 5c53fc6d6d29d37ae644bf3845ff851d6b03cd26eb5e411f93c26dcf018a4c35Virustotal results 27.12% Quakbot
2023-05-18Vmyptzx.jsjs 17c3055ce856c6ee8bbfdfa36ea81dedf3d495e3aa418145fea73358747d4cd0Virustotal results 25.86% 
2023-05-18Mcbuq.jsjs 7b0e64b5b88495d402a11b16ad7776cc5e0d44a07992e8b9cf9c7006a92ac8bcn/a Quakbot
2023-05-18Olptjsu.jsjs 19add01de5eb9fa85d7bed9badc8daf24f0083faf06b7eaecd8b1efb21be5428Virustotal results 25.42% Quakbot
2023-05-18Jymx.jsjs f0dbb6e29c6d7e8d5463a1e716423776b0aa2be9fedbdd957adf165559ca8a5dVirustotal results 28.30% 
2023-05-18Wuvspaca.jsjs def1eebe55f3bc428d1f39ef2f6c7d61a64a48dcc71389a348eefbb797e07653n/a 
2023-05-18Fcttz.jsjs c63bbe3dc673315fe3da91f26e53709a754546f9d2fe9fdbbd7dfebbf28c116fVirustotal results 23.73% Quakbot
2023-05-17Hnfggak.jsjs b65cfc5c1f188f590ab7d7d6a20d1ea638a086a9be61e3442b6ea9388fda3c0cn/a Quakbot
2023-05-17Mqrbfygg.jsjs a0c936769d05f511e808dc9d178d44c1b60779ae7ad0e7424e520b2e75ce335cn/a Quakbot
2023-05-17Qaqbawa.jsjs 34af4640c3591095a1562606faa096b2cab669c17859f8b99df4321999b17373Virustotal results 22.41% Quakbot
2023-05-17Ozqcgjdm.jsjs 26a9ccdd2cb5bd68aea8b06532a4945f8f6585f5ee8e03fd64c7dd7ba9bde535Virustotal results 27.12% Quakbot
2023-05-17Ddbm.jsjs 7f5092d0b223ae713b6ead45d62c1c63d910a500fc960aeae16e1a1073355c86n/a 
2023-05-17Lemqhd.jsjs 0281a8abb9cc25356770caa1340573c19ab7bda7d5303f43a60a52b2b9154067n/a Quakbot
2023-05-17Jpbcvump.jsjs 4a5bb0d1af42aabd643a23c518cbc77c4a2931fab8d180bbad1c0ea815f5954an/a Quakbot
2023-05-17Cjwb.jsjs 5b939c07e76fe301a66b2613a2e0a9b289b0ea6e468cef398b58bdc202465aa7n/a Quakbot
2023-05-17Jklehlw.jsjs b4607f4e324c4486d0b09262d9bc4bdab0ea0143c5aa49fbbb688579aaf67d6cn/a Quakbot
2023-05-17Iitnkqqa.jsjs 19634bc5d277bd2ef6f47daf49184306fa548e848ceecf2686aff981b80d822cn/a Quakbot
2023-05-17Esxo.jsjs d424fdf0b7f944b4b56a4aa5ebb3b9350e56ae670bba0a067b52d6cdb45e644en/a 
2023-05-17Hbyo.jsjs c07ffac9b1d36a0d280fd711deeb42679558110dbbffd46a49c3bf122d753089n/a Quakbot
2023-05-17Zbpgq.jsjs 9e3931f0349989c7992625b9b609bbe6fb29ba89c621dbc007061e1cf254a142n/a Quakbot
2023-05-17Jiwjnn.jsjs e7c37318d38fb7d3bb26690f255cbf2273e28aa698853b0d78e194ba82d4ca6fn/a 
2023-05-16Buxb.jsjs 2bcd1c4e227e0ef7ad928860ded667e2987c6d6f42c87618648b7116f033b9cfn/a Quakbot
2023-05-16Wdrm.jsjs 149631d6f2435ff196cfaa5feec53cb3d818746593f610b3906fe6fa962a72d9n/a Quakbot
2023-05-16Wodni.jsjs 62449414b6bfbeba9ea09496a79b5b01f8d26855deeecbd1ecea9100ccdbcae2n/a 
2023-05-16Jixmehti.jsjs 209c2aceaabe07ec79169929195b8e872469414b44423339d518670e7ff43950n/a Quakbot
2023-05-16Elaartjp.jsjs e78dbbe3321fe1cd1c6118d8feb0bc3e09c891dffcdc95d4e57bd9900ed0312bn/a Quakbot
2023-05-16Kaata.jsjs 7e896b31df435b8140458865f16972be71363f41889fe402fb2a21f07aad85d4n/a Quakbot
2023-05-16Zugldlg.jsjs d8cff6bcce410268e0f5bf9089e1c09319e92faa76b05685c0d280a565199910n/a Quakbot
2023-05-16Bnowbf.jsjs 57e114b6c41d88d51490178c3230972d355e3ea0e0479f24d5fa09090f07e48fn/a Quakbot