URLhaus Database

You are currently viewing the URLhaus database entry for https://assesgroup.com/ae/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633634
URL: https://assesgroup.com/ae/?1
URL Status:Offline
Host: assesgroup.com
Date added:2023-05-16 11:25:39 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:27:32 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:2 days, 10 hours, 40 minutes Poor (down since 2023-05-18 22:08:27 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Dlsvf.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Font.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Zdarx.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Dckzqnl.jsjs 3cd9e996554048f270e25974d8ea03a2d571a562bb5f61e48aaf1c4ad43a534dn/a 
2023-05-18Crzsqdd.jsjs 07b159de000e3d081a5de88077364dcaec1eff528f38b286c7ba65059429853bn/a Quakbot
2023-05-18Koudjhxi.jsjs f7bc14c8c137444d5d046f1c1304ca9eb96509ce61adeffaa967dc07f21c17d7n/a Quakbot
2023-05-18Fkhi.jsjs a569ce1eb1902d2edf7cffba78e832e764170e48ecfe81ac3adda07c5f42455eVirustotal results 30.51% Quakbot
2023-05-18Zjnpoip.jsjs 38994d258f8bfb97fcb4ad671d962c6f000efb90f29ef01a8ca9881d7a206c66Virustotal results 27.12% Quakbot
2023-05-18Qrcvm.jsjs d112f357338680817dc9cfe7ce64d7ab03de74008f16c43f1ef94b38bd159af8n/a Quakbot
2023-05-18Gdqxijsr.jsjs 229271acfd7face73c4919f8ae74ec7e9e3d276810827e045c7ee12baf2e75bfVirustotal results 30.51% 
2023-05-18Hpjgluy.jsjs 71399d25c8497d7f81c87b8f5ec8d5071d8a62ac85ee254638bf8d24feccc5adn/a Quakbot
2023-05-18Mrqmjh.jsjs 8110c40ddb65d964d81ab30f4c4f9bdce11b8956b986d647f4b81c4c0652f5a3Virustotal results 31.58% Quakbot
2023-05-17Zvfkbwqh.jsjs 714d6297effa9020249e19940853d50dcb2ba31d5301a716f34ddf73f9a58bf1Virustotal results 28.81% Quakbot
2023-05-17Ghpg.jsjs 42d74e9be0d442e0bbebc6134157922913abc72510b235bfa67b53092757a2f4Virustotal results 30.51% Quakbot
2023-05-17Axlgyxm.jsjs 37dfc4f0a00904e349fd56b330748fba27b43ebad14ce22ba20df17809091c27n/a 
2023-05-17Sdazn.jsjs b896df419a5e1ac8fe67ede2b9594d6252e8dbf87ef64fd093ceacc52a84798fVirustotal results 24.14% Quakbot
2023-05-17Uhbbg.jsjs 8116e7914df0a4fae9adad12da668660206754557fac016131c53fcd305d537fVirustotal results 32.69% Quakbot
2023-05-17Bpvsia.jsjs 356497f781814842756d631b841bd2962b7aba15e1e749956f57352ecf4e24bbn/a 
2023-05-17Llojkpk.jsjs f0071ab8efac63f43a57e5ce10cebfd8f2d18f0b8df63002a484d4acdc24b4dfn/a Quakbot
2023-05-17Qzrqu.jsjs 1eca9bddf9461819f0f6b5abbf671b2b97f20296952e16ffae75fab87ba330bbn/a 
2023-05-17Pwdh.jsjs 69936e741bffdd076c147f9f148f8a4483ce2c50b7bd286752e60e7375f4eec1n/a Quakbot
2023-05-17Jwkpq.jsjs 765c140a454b9b0646435fd7a2d836ac74bd5804a2d57c35c5789c7388e7524dn/a Quakbot
2023-05-17Lwipmbr.jsjs 494b6db56c63902ba4ab968353bed82350c83880deb111f147d52b71db489198n/a Quakbot
2023-05-17Gtfe.jsjs ecfa59861936e2b59d62f72705aa5d2ef135f09bb40a88f1a639bb7c47d6d033n/a Quakbot
2023-05-16Yurpwxgp.jsjs 09896515dc6c3f9d62bee1c87103f8c2f332a8e8b8affeda918f51eb9e148729n/a Quakbot
2023-05-16Kplko.jsjs f1823a632111093e9e2414afe7778a6c966f6640d370cd3a25fadbd06d4a65d2n/a Quakbot
2023-05-16Wlerbtv.jsjs eb65732bd97265588430d801b08164695247bcb37ce87f73bf3507047ad769f6n/a 
2023-05-16Tvoa.jsjs cf6d557f46ce4de16c91021ab16e177b41d88934deff44f234c24c31aa07d1d7n/a Quakbot
2023-05-16Qhegfv.jsjs 5f71fd4f94ab3ab7eaa4d109579a9f400948fb28e591becb8e0208d0b279f278n/a Quakbot
2023-05-16Jfysfqxs.jsjs eaf4d87d4705f31fb373edaca5c357f4052d4c5f53508771d65abf09892a2d87n/a Quakbot