URLhaus Database

You are currently viewing the URLhaus database entry for https://cebelgelendirme.com/gt/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633603
URL: https://cebelgelendirme.com/gt/?1
URL Status:Offline
Host: cebelgelendirme.com
Date added:2023-05-16 11:25:30 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:26:37 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 11 hours, 21 minutes Poor (down since 2023-05-18 22:47:55 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Rghzvx.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Kimkep.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Zrgtyll.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Ixcfs.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021an/a 
2023-05-18Qupa.jsjs 628711118224788f9a64179c9c9dda12c9cd363d7c30f3e9a6e8785fb307ec3an/a 
2023-05-18Rkwioj.jsjs 9da26f54018ef7b69e7ca172d1ef9d1de643acee030e0b25c66a5f27867c8833Virustotal results 26.67% Quakbot
2023-05-18Ynnqg.jsjs 029c7e0d1aaf9b325f8d1adf729b367d04954a895d6c1988c91f700855d91db6n/a Quakbot
2023-05-18Buhv.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2Virustotal results 25.42% 
2023-05-18Ozuhnb.jsjs 106ea6e9df2db6267999fa9df4ae5950c1be2de07cbb773cd739bfaa29a806d4n/a Quakbot
2023-05-18Ltjgy.jsjs a5e07fd19c36096b65281a4da6788fdb724e4cc4be6fae21497a969c1255a622n/a Quakbot
2023-05-18Jkzj.jsjs 2971e245d875fcb96bbbbcff59e1a34e0490ae85f5e8abd688b28772bca0b30fVirustotal results 34.48% Quakbot
2023-05-18Uctsquyw.jsjs 8d8b15db563271d51b6caabd1d280fdd09e2262383534714503ad6903b1dd6fcVirustotal results 31.03% Quakbot
2023-05-18Faqovel.jsjs 3f14bbee3c8ce3a67b5dfc257b5cff8e6f131ed1b17c77a50e705cb44af1c616Virustotal results 22.03% Quakbot
2023-05-17Tarhc.jsjs 285384a5ccf94492475a9af926ddb24dc621f5b0f19df79f8ed7366ca130d544n/a Quakbot
2023-05-17Furci.jsjs b3455e378aa4106c5a643052bdcc324c67382149a5eb84a546fdc26f4b5f412en/a Quakbot
2023-05-17Ewmgff.jsjs e5e55c026d33a226eeaecaec0b1f0e887452329d55151ca363f093722745e770n/a Quakbot
2023-05-17Exxoten.jsjs c408bd9762412a5776d177862b5ac082170428db1332d9ba6c28929b506a4858n/a 
2023-05-17Pffbpxob.jsjs 8f5bae7c3310650dc125b9223695f4a40a6d1394f6f6f9dff466a3e53099ba7en/a Quakbot
2023-05-17Aknac.jsjs 5284d5807da5986ffb17fdd9761066974cb34030eb5067e7f9a65e48b32f37e8n/a GuLoader
2023-05-17Migalfn.jsjs 4657c8d962a15da8cdc6ff3c1ab3d492a89eebdd09249e8d29eea382791500abn/a Quakbot
2023-05-17Gsjjp.jsjs 531deb6f64b171916d207a8ce8cfb0dd0e6cb7e8343c2dd55084af7b88c6de81n/a Quakbot
2023-05-17Qugew.jsjs 3d5c5f25072ecfefa79e35511e168bae3ecf392722dc09c5856ce8f17dcfe73cn/a Quakbot
2023-05-17Bccv.jsjs 190200750625e95ae8ff46cd34d61ccefb0b093ad6b7faaa80696a52be0165fdn/a Quakbot
2023-05-17Tbrbaa.jsjs 14f441ae972a7fb53570bb3250de9b1900c2f5db4f012080baaa7315a17228dfn/a Quakbot
2023-05-17Rbmfk.jsjs 701a3bce5a085d5e9d21515f63d7eb7920cb3919f928c0ebaa1913e7fd3b0d15n/a Quakbot
2023-05-17Iximyvk.jsjs a6b5ae1003ce34ea40723a8141492c2c7f51568396e9185d4892e8a4a19b3cfbn/a Quakbot
2023-05-17Exbdyhv.jsjs 43606d4b84d2a89332c6a41fe6fe1d6a03b0dc74b8145ccef8f0f02843e2dd86n/a Quakbot
2023-05-17Ecaiiu.jsjs e0313bf2bbbb64755029f5f80c826d3f30cb06742d00a400a4481566c41034fan/a Quakbot
2023-05-16Cpaan.jsjs eabbf01d914f81b21dc8047a099cef0d9e62bbe8be7c571b28b7a0f8d450aeb2n/a Quakbot
2023-05-16Riad.jsjs 10122ddd557531c7adde47b600740ffb54e30c0971829112602eccc99640fb4fn/a Quakbot
2023-05-16Txnf.jsjs 28f0d7dbc7ebbc24737119266375a58fa52139fa0799b973131e0f6bd861a69bn/a 
2023-05-16Ohkdqgi.jsjs b416d160a571dd655362d952a555a772a12dbbbd79f236c200c1a0705fb0b048n/a 
2023-05-16Rjbntznk.jsjs 4cd39f8674a2fb87a448193cfc19e22bacc215fae1ed717342d4a1c81f6ef714n/a Quakbot
2023-05-16Zofxcx.jsjs c9795a5be8991aec374eafcc16c1967539c7f41925b46b2d1083ed531eaf86d0n/a Quakbot
2023-05-16Uwkrdxt.jsjs 4a02d35140167eef0c8323a4764fb1194de86abe4a9d5f4de4d669bcad97e52bn/a