URLhaus Database

You are currently viewing the URLhaus database entry for https://astrologerahmedraza.com/psi/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633618
URL: https://astrologerahmedraza.com/psi/?1
URL Status:Offline
Host: astrologerahmedraza.com
Date added:2023-05-16 11:25:36 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:27:33 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 10 hours, 41 minutes Poor (down since 2023-05-18 22:08:49 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Eyitcts.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Zirwsi.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Qizjhwp.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Cjvf.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182en/a 
2023-05-18Plmsi.jsjs 9f16a38888bf7c130dfc15dff72eda59b2621e7c1048f157a4cf51e9bcb2e280Virustotal results 32.20% Quakbot
2023-05-18Pnwov.jsjs a4fb26b40f74df15f85f6ee98f0faab524e9434e8469ea400fb9e1d4a53e6505Virustotal results 28.81% Quakbot
2023-05-18Ksom.jsjs 55958c9aef4b48e1d2648546d04249950dc900677dbaa6883bf95cc5db2df09aVirustotal results 23.73% Quakbot
2023-05-18Bwnukssn.jsjs 6cc345a8ad3df8d8da07821f31095f9c217201e0065038c5bb7e15aae14a9035n/a 
2023-05-18Yjqfac.jsjs d2ecbbc4d10634ac3f47ce638df6c4302d7335ab985c09f6accdfe4df322dddeVirustotal results 36.21% 
2023-05-18Etjo.jsjs d3c173c2dfa25e646847bc107890d76906c807bf85968b5dd9e96044a7729b2fn/a Quakbot
2023-05-18Lnfgko.jsjs b11fc0e56235f908dd870eceed98215c815c131e83913eff33f70f528e369dd4Virustotal results 30.36% Quakbot
2023-05-18Qwvyqc.jsjs f6d73eed4ee4cb252294f53568ea49c055a4a65267b79e8491ace852655d5575Virustotal results 27.59% Quakbot
2023-05-18Udjitz.jsjs 24579cbeb7c33196bff853d67ce422776e45c942b057519eb6a6c453ed30ac62Virustotal results 30.51% 
2023-05-17Jrlte.jsjs d1a4226b93ce7e197a1d0a500323d097493998ae6d92816b4793bac2150218f2Virustotal results 27.12% Quakbot
2023-05-17Zkmojzc.jsjs c321a1664d74da4f73b983c793c4059b38202d4116be2e9f53f9aa1d4320d830Virustotal results 24.14% Quakbot
2023-05-17Snxqireq.jsjs 3bb4e5803055d8c3ad6250df56ce21b663c3da855bc32daa9ecf204060498681Virustotal results 31.03% Quakbot
2023-05-17Dqfvcede.jsjs c6acb46e483e7792474a50acd3a7ad70626f538da57050c7153b3061376b4f02n/a Quakbot
2023-05-17Upfxuf.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-17Wemlhaev.jsjs 939b394768f864f5af2b1e196cb9982563bcbf1157f23f9a873030ba262566c3n/a Quakbot
2023-05-17Gykgi.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2n/a 
2023-05-17Ksscezd.jsjs ecc2fe303a55fd989c99ca2dd02963f2d0616d263f69f3ed684e46039a88d590n/a Quakbot
2023-05-17Efvc.jsjs 4eb60e4974c48ac4ff3b1a421d93f3c63d76790b45e1c46c2b4857ae66e9ae37n/a Quakbot
2023-05-17Rfvstn.jsjs 72267a34b3e93ff73ebb04e740839460e5960172fc9d934b894368375f10e99cn/a 
2023-05-17Zurkjm.jsjs 14fd93e24a3dd3442c252f6de325ff3bdcb299eeb7f8a8cc47f7fe33a0d7f9e4n/a Quakbot
2023-05-17Howgzcgs.jsjs a15527c7c301d0e40dfc7cf26812e018a728fce249a6c9b2b8b9b25d16630b4an/a Quakbot
2023-05-17Mgof.jsjs fa1c08165c2d3e8bac82c8da63fc3b05540d4a92499be032aa5077a12bc6e6e8n/a Quakbot
2023-05-17Anwvltd.jsjs 69f89b9aa2ebb8b3443f9d3ab39cd23f3d6babdb3ba6dae6f4a4a1bdd75c2ce4n/a Quakbot
2023-05-16Maxskvki.jsjs 3c588bbb8b437938393f8714b5778433bd16473a20b5a3b9cb97990e08895008n/a Quakbot
2023-05-16Dxbhv.jsjs fa20a90b5be3be9cdf7b96e60fcf24165083c2c5ec3260d24c83fed9504e98d7n/a Quakbot
2023-05-16Eztmrws.jsjs 1c0f59116200324f316432d75e59e370139a37f671073c3fb70094f7372f321bn/a Quakbot
2023-05-16Nghdftx.jsjs 02a09d5946987897a7c799fd759e7a2f357b6f3fde761bd19585a8effaba6576n/a Quakbot
2023-05-16Nmyeqz.jsjs 50221808a42871506ce709b9b323e8f1479b8af228c599ea24c4eecb98d22132n/a Quakbot
2023-05-16Nnhbpse.jsjs 8e7f591997c52fed14230eb37d5ccc774296a8c05d49fde01d1bee266ca32349n/a Quakbot
2023-05-16Mvbal.jsjs f12930f68eb1d94827cff0ab30d6c43053fb526513697304ddd48ffd45b8df91n/a Quakbot