URLhaus Database

You are currently viewing the URLhaus database entry for https://realtouchparis.com/aqa/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633564
URL: https://realtouchparis.com/aqa/?1
URL Status:Offline
Host: realtouchparis.com
Date added:2023-05-16 11:25:18 UTC
Last online:2023-05-17 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 01:20:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 10 hours, 5 minutes Poor (down since 2023-05-18 21:32:15 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xfbuywb.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Kudkglmr.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Pruwe.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Msajed.jsjs 4946ec6dc04754f0c7f1e2bb7cf37603d9ff89bdd06fb7cca64ac470278421e9n/a 
2023-05-18Ckgs.jsjs 1d2471f7acbab8882ea6f628275c501f0f81e0aeab5ee16537702bd849e8ba6bn/a Quakbot
2023-05-18Vpdhsxs.jsjs 3f14bbee3c8ce3a67b5dfc257b5cff8e6f131ed1b17c77a50e705cb44af1c616Virustotal results 22.03% Quakbot
2023-05-18Gsexvw.jsjs c5cd6ca0ca7e79a3c24d0b2e608780ee8eff700153663539c8be58f273a24565n/a Quakbot
2023-05-18Bgqijmet.jsjs 939b394768f864f5af2b1e196cb9982563bcbf1157f23f9a873030ba262566c3n/a Quakbot
2023-05-18Nzlyvpxa.jsjs a45416e3d9aa47760feeee7375be42c3748b04b0d9c6c573bf4db2cfa07929b5n/a 
2023-05-18Xmigkkjz.jsjs 3dfefc0e91ce9c601581448bcc12aa145f0ae317f0c3bf6cd09b4605cf679ce0Virustotal results 25.45% 
2023-05-18Vgqdpbd.jsjs 7e29b555dd10291e663446073640ea5519a3e38a3655264511bf14299c86dccbVirustotal results 24.14% Quakbot
2023-05-18Vasp.jsjs 5195290a6bfe72d1709c08345d0210181ab60e363339796ef44c05a17d9c03dan/a 
2023-05-18Jbtyw.jsjs 32786105579d9ee90c2b3e3c5c1aa115af93c9931e8629901c02b41150fa1636Virustotal results 27.59% Quakbot
2023-05-17Fhktm.jsjs 3fddbe5cee0b2b8ebbfc9637b8f112873fa786d04365ec85c4ff1f3ef1962ce2Virustotal results 23.73% Quakbot
2023-05-17Cfapnte.jsjs f27926066b5633ef279634f13fac70b4fc198ce37d68ef22e07fa19e4bf0fd44Virustotal results 27.12% Quakbot
2023-05-17Efpkcbeb.jsjs e6823880248255f28dad73af6553cfbae133b6df9f78eff124a379d793265ac2Virustotal results 27.12% Quakbot
2023-05-17Thyozu.jsjs e097747aa43ca0c5787d98ebdab3ab67fda12444d287a4a0702a670f0b2494d3Virustotal results 11.86% Quakbot
2023-05-17Zmzqp.jsjs 0efda647b9e6537d80702573e14dad4cae7edd5bb92d94eea0f136b93fdc03b7n/a Quakbot
2023-05-17Zojpaqrj.jsjs e78861a712a577b61558f7ea9878b91e974692081e5daa5f02dcb5ff1cdc359aVirustotal results 32.20% Quakbot
2023-05-17Qvrokev.jsjs d4048bb4d8d517078d21db74a0238b8f0696dbad0bfb9cecbe0dad5e3a89bb47n/a Quakbot
2023-05-17Dpbuk.jsjs d093e0cadccc6d3df841fc4b9015194147fdb0a813ae45a66bbef6d6943180dcn/a 
2023-05-17Mqzzfs.jsjs bddc8fab3c22ca9ff9ed1fd1037c6e21c8ce2a5d3940224bfe4564250fd28003n/a Quakbot
2023-05-17Cekdlvd.jsjs 3bc8faf0ac509430764c85f3c1d79d59ef8407c85ad430a3043fd23a30faf9b2n/a Quakbot
2023-05-17Sxevj.jsjs 26682742251d0917bf1a6c59e604c123e21c9f4b914be0ebba217290db3e1f90n/a Quakbot
2023-05-17Ncuxwtq.jsjs 2122a43ada1546792fe3b24e465ba5866bb7f13b9d15e29d2d05dd54e3cf0439n/a 
2023-05-17Fydrmbao.jsjs 42c207ee496a123707aeb09976d633373d162baf5fe3a6bb066f3955e72e5d70n/a Quakbot
2023-05-16Hprcv.jsjs c5eb52313ee2301a9e0eebe662facb697a082ec0a389158c85befc5748244e11n/a Quakbot
2023-05-16Bipfuwh.jsjs ec7c1c1f60bd6978c60c2232b824afdfd5f338102ba22b60917aa45456daf788n/a Quakbot
2023-05-16Kmxsgq.jsjs d8f1a5dc47e84432a1971c0a82cbffe21da3362b1956e6ec0d3c5b00f383d759n/a Quakbot
2023-05-16Mswa.jsjs b81a372a9560c0a8a973e0accefec440214a79335bf33a08c15ddda875cebc26n/a Quakbot
2023-05-16Kvvs.jsjs b2f5a4579a91778a7b523894d4e89c1c975aec943c84df34fa83c319f7911d94n/a 
2023-05-16Pkeqykky.jsjs d112eef5d2783914d9b9302f5c8de05f9597915aa2aaa662f933691b0c87e3e2n/a Quakbot
2023-05-16Qolcf.jsjs fedeb720876cb6bf610e313bc3c404f5f3bc609c21b537018a07211138438998n/a Quakbot
2023-05-16Yonlgh.jsjs 847cf544ca9d6880666ab9335715f77a09c82d38e7024a63a8a96e1c5db01026n/a Quakbot