URLhaus Database

You are currently viewing the URLhaus database entry for https://cycoolsports.com/orl/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633597
URL: https://cycoolsports.com/orl/?1
URL Status:Offline
Host: cycoolsports.com
Date added:2023-05-16 11:25:30 UTC
Last online:2023-05-17 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:27:14 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 8 hours, 54 minutes Poor (down since 2023-05-18 20:21:38 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ibwya.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Fxbzn.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Mhun.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Hkomvbzi.jsjs 91a5198c948c77a1f4e846013f6bb7d2ff376ca399e58f825e90cfbaf5c3c773Virustotal results 25.42% Quakbot
2023-05-18Fooarob.jsjs 24579cbeb7c33196bff853d67ce422776e45c942b057519eb6a6c453ed30ac62Virustotal results 30.51% 
2023-05-18Msixicdg.jsjs 875bccb572b756073e35cf697abde47c18a8fc4156b093bd6d229ef766faed99Virustotal results 28.57% Quakbot
2023-05-18Xinzkzjp.jsjs ca9502bdc52560b18884b4483fd8adca417142d736bc92b2039511c11483e4f0n/a 
2023-05-18Zfzovyxi.jsjs c82de2729716408ddf8dadbc7c96d591774e13040bd782c4b2f6f56ee2b039d5Virustotal results 30.51% Quakbot
2023-05-18Xmkzthk.jsjs 20336fdfef9d5684dd6055ff838104e334316b82122b0a12b809b529b1a66cefn/a Quakbot
2023-05-18Lxzblts.jsjs 0b3324b249fb9e33cb3970056ed6166b271c1f678d65d34cdff6079bbd95f2c5n/a Quakbot
2023-05-17Tehwbdi.jsjs c3f8749b256087bbe0dcc6d662f467c1d34f701e65acfb75292a72aba0657e26Virustotal results 32.20% 
2023-05-17Tdumqkhn.jsjs 5b03a98354c24b442061c45caca4e261ba88fe1d68187bd4c44f84773d562a6dVirustotal results 22.64% Quakbot
2023-05-17Dqirs.jsjs 882f433be14420954cf276d10abb6b832e89ab1dc301d2d047538fab217afdabn/a Quakbot
2023-05-17Gweo.jsjs 72c9727d22512473f4aa27d93e0c15ae33a95784d9804b057275d0d7d8b0a361Virustotal results 8.62% Quakbot
2023-05-17Ycyip.jsjs 3e80a8823bae07e1aca749a62a6da2c57f0f80ebb6d4a8cd1be2ea749d3af45cVirustotal results 13.79% Quakbot
2023-05-17Csxsqyw.jsjs 2c6c3f6ffb898b9a29cc0a5ec84ccecf30800496946b378d5558f81798278c3an/a Quakbot
2023-05-17Mwqagnbq.jsjs b4a90889250c70642150c7b822ece35979290cb3664a5f778ccb8195b4c440ecVirustotal results 25.86% Quakbot
2023-05-17Exefxgs.jsjs 9fb9192d902b2bec0253263ac7de12696284a3203d04c735faf491c94c94ed32n/a Quakbot
2023-05-17Bbnuaxa.jsjs 87cecda1344bd96d3443371baf8c484feeec4a837e042ae2543df1bbffa29669n/a Quakbot
2023-05-17Oyimmlc.jsjs 8842c98cf1fc25d03c407353c7ae297b12941b310dfdc786aee98e315ae92f5fn/a Quakbot
2023-05-17Gcgcujuw.jsjs b422da7368d96964a5e6b7094d2e5e85b6c13e63a54a6b9619dcf1cfd2e08f84n/a Quakbot
2023-05-17Wmmdvz.jsjs ac37e7655009b792e6273bfc0861c816458a80d9984df032e85ecfabb0f8ce9cn/a Quakbot
2023-05-17Gdrylr.jsjs d0dbe996316d50660b7ea20ac58f7737a47f4ef717c3e53446f60205774af463n/a Quakbot
2023-05-17Bjvg.jsjs 8d5e0742521576f55b9e094336220a16a5a2eb14869e3f3c2fcc61743f8dc9b8n/a Quakbot
2023-05-16Woffy.jsjs c1e7b973ca86dba04908af2c7d3ad76be367ab564a83eda33cb29722ea7dcb92n/a Quakbot
2023-05-16Xnwuyf.jsjs 23f2dbd88a1f5cd54dc71e16f6cfc8702507ca9e9563b421015835f04df6ba45n/a Quakbot
2023-05-16Hmvtu.jsjs 5453c2e443329e6f4a2480ac0242900aa0bebc711150f5ff5b5395bb7227e334n/a Quakbot
2023-05-16Toqt.jsjs 010a844ac9fca8e0dc54b2c095e4aa62bdffc6ff673b5c522125f3a44d39c1a9n/a Quakbot
2023-05-16Xrimdbpm.jsjs 3dddeca1eb2ce13793f2370dc0a712cf176e37536deef5a7f5e51406f1d426e9n/a Quakbot
2023-05-16Yzajyll.jsjs df9653de381468f572376b2076a8df68a88dd0edf0e248493aaa192b0e705adcn/a Quakbot
2023-05-16Zxjdtcm.jsjs 8dc580abd53c24fcd6f0a6962c7b62ba4d8f67688176ac91932c0c533ab151f0n/a Quakbot