URLhaus Database

You are currently viewing the URLhaus database entry for https://aoscompetition.com/emu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633625
URL: https://aoscompetition.com/emu/?1
URL Status:Offline
Host: aoscompetition.com
Date added:2023-05-16 11:25:38 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:27:39 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 11 hours, 25 minutes Poor (down since 2023-05-18 22:53:14 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Dzwe.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Nwmjl.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Qjvr.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Zawpk.jsjs 39349cb32dc62033a2873ba37de59ab9b53950e12609264e1e0ed47d3b20e375n/a 
2023-05-18Wbtp.jsjs 88f6a8cb20802cddd090c331d20f9642aed6deeda17214154bc2017f911d61c3Virustotal results 25.42% Quakbot
2023-05-18Srvmhw.jsjs 45a695a6696ee2284f34ef03f76d7192a3829a64f1ae5f5216bfd36983231680Virustotal results 26.67% Quakbot
2023-05-18Kmeppws.jsjs 783e0a457afb1237e0956e6ff847bfcdb49ee23036f51b4621b534f54d67112cn/a Quakbot
2023-05-18Ujhusty.jsjs 5848de38e1e0698b0e24ebe9bf6c45ef062f0f7d7dd7444e4a32d6731d5802aeVirustotal results 33.90% Quakbot
2023-05-18Efzmazi.jsjs 320db1d64ed5a7a4ed401ebf9861a9776e220be46c59f4113bebf562f9e506f3n/a 
2023-05-18Ytdoq.jsjs 8116e7914df0a4fae9adad12da668660206754557fac016131c53fcd305d537fVirustotal results 32.69% Quakbot
2023-05-18Sieethc.jsjs c73f356c704556ac74d752c91963fe6a1c7273b77027b218016b83f03ca878eaVirustotal results 27.59% 
2023-05-18Kcfrolec.jsjs 78416fcca7554fb3cc440610418511210e0dc5abcebf75ace7c1ef65d4d29216Virustotal results 25.42% Quakbot
2023-05-17Nakvsqy.jsjs 24cf08aad92d93dfabb65546276958ba1bad72825e0af1a4fe5d2a2f0d2a451fn/a Quakbot
2023-05-17Evgy.jsjs 1d57c903d9a9f7a6aafe34d3d44ced534b1878b64b93029c391c25c05c708094Virustotal results 24.14% Quakbot
2023-05-17Idcnyy.jsjs f44e30ffb57afcf688c00896ca7384786ee3ede05210094b66c6d9d6c83675e9Virustotal results 18.52% Quakbot
2023-05-17Lntl.jsjs 17dcb0baeee21444da6b254c7dcd1d98989c6a0c089b8d79530a2c2a83dc34d3n/a 
2023-05-17Nwcorg.jsjs 5155a314d6e44ed6eb4d65e80d368d8bcd4e8674e293bce8d712b03395d22f6fVirustotal results 11.86% Quakbot
2023-05-17Tulz.jsjs cd8a39cd43a8cbb2e0c04b201b7df230226fe2dd696ab5c20c9ecbb16cc723f3Virustotal results 24.14% Quakbot
2023-05-17Vqdx.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-17Bijmcofs.jsjs 6341f87ee4bc63114ac2e7899107fa341aafda80e5fa00f00b0f72d89ddc06d9n/a Quakbot
2023-05-17Ckcb.jsjs aa6d011f5cc80e3be1a1853a4640bd56339dcf37bee4efc146dd760fb54839d5n/a Quakbot
2023-05-17Hhvrfaq.jsjs 6a9706cac4f1645eb14d3f1eff867216aa75d2bb01986dd64fbe715587c52d65n/a Quakbot
2023-05-17Igomxcs.jsjs 2beb5ccc044370487a6f8dbb86dcb6383b3849b9502f7c837214365d297a9929n/a 
2023-05-17Tegvfa.jsjs 95b4d397138336c66ea5f04c9fb0a2f5cd2bdd805cb90099c96406ba40a83d3cn/a Quakbot
2023-05-17Nnzmxxg.jsjs 584f326c3e45df0c4a0308f593597f2b537aad61596781e47970355781e7526fn/a Quakbot
2023-05-17Xnkmi.jsjs 02ab2572078424f1e3ce51a67d8308cdbc5051615d0368a9e42634bd7a8dc167n/a 
2023-05-17Wxaxny.jsjs 86f38fb657df4b9d61636158f4e027ebb05088cda00b449d36a92b4fb9a70913n/a Quakbot
2023-05-17Lxui.jsjs 885c98b1a37288ffd401e798e8e7ce0b07da0e55ef5493f7a63dc2d466fa9664n/a Quakbot
2023-05-16Xqtrm.jsjs a2faad8ba97cedb72ad6499e4686a9f07bf1cf7ae71eff7c550d73676c3f3e1fn/a Quakbot
2023-05-16Mfhga.jsjs 34e5e41f44d95f4d3e86f868a955111307d6b7012d1af7d941efa55faad17df8n/a Quakbot
2023-05-16Jfqwj.jsjs 714b8159ceceb36e70cb696f58b0b3efefd88a6157ab900daa57033bd56ac0dbn/a Quakbot
2023-05-16Zmedd.jsjs d8f0dc5919db9dd45912ae6ae13cd7c10f14557b7795438dc4950fbfd86a62bbn/a Quakbot
2023-05-16Cyjg.jsjs 23d6fbf24354a710def4a16f0edf197e35cc46387e6ba5a670e215caa5816b69n/a Quakbot
2023-05-16Tktcm.jsjs 50bc0d13d917e81fec29e02c7559290f3e7b61df99e2070080fc0e40841c59e0n/a 
2023-05-16Muggdu.jsjs d256075f9733fffb37baa8e647637c7fdb0055e977f77600dc8d573655d5388en/a Quakbot