URLhaus Database

You are currently viewing the URLhaus database entry for https://cbtexamination.com/xeni/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633639
URL: https://cbtexamination.com/xeni/?1
URL Status:Offline
Host: cbtexamination.com
Date added:2023-05-16 11:25:40 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116411 created on 2023-05-16 11:26:10 UTC)
Takedown time:2 days, 11 hours, 21 minutes Poor (down since 2023-05-18 22:47:14 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Zuvfnvd.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.33% 
2023-05-18Cypkfvti.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Zpaf.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Vzwekr.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcn/a
2023-05-18Nzmgjsnb.jsjs 17da932080db984c8594c50184bd0cfde690ed29cc7cd73f3136474e2cae191cVirustotal results 32.20% Quakbot
2023-05-18Hljdy.jsjs d298331f4833111dff68336933087e322debd03460a21ee0d22d0d8e2b5f7ca1n/a Quakbot
2023-05-18Zaxfw.jsjs 92541d594f60bdb46e24073e3720e0deb32a8bb5a4409a44b650b790dbeda309n/a Quakbot
2023-05-18Fexfihq.jsjs 7ace3a86b7ee25c1f0e953e1c7228cc835205c53e5ed210b4f3b7fc4291a75ebVirustotal results 31.67% Quakbot
2023-05-18Wgnzjbm.jsjs 3a16d7765c95e4f1c085fb18814d67ba3d65e6bf93e38d064ef74c1f9d15ac83n/a Quakbot
2023-05-18Opgnv.jsjs 0857b5e40844024689620ed0e9d9fbef8b9b295f54e11fba7dd9693f59ce40fdVirustotal results 27.12% Quakbot
2023-05-18Fgir.jsjs 32786105579d9ee90c2b3e3c5c1aa115af93c9931e8629901c02b41150fa1636Virustotal results 27.59% Quakbot
2023-05-18Llvyuw.jsjs 4657c8d962a15da8cdc6ff3c1ab3d492a89eebdd09249e8d29eea382791500abVirustotal results 28.00% Quakbot
2023-05-17Tnnuqwbx.jsjs 076515d52f5219c37701ac4b38e72e4f6a809dffce463343615c3fb079c9ec89Virustotal results 26.67% Quakbot
2023-05-17Wqsu.jsjs 55de6657c16f6c71d27bc0cb38580d689241943b653c659ae89fd4b63fdc279dn/a Quakbot
2023-05-17Ymoy.jsjs f5a9de314dd0e63ac6262d4d17d66999b1a0ef8384756576c26eb7623a678f71Virustotal results 25.86% Quakbot
2023-05-17Hzrnqpw.jsjs a87f72f4479c91e3e36a8b6a204a7d9169c1e604389f6818744f3bcca14fd959n/a Quakbot
2023-05-17Nlqoebln.jsjs 90d7044e2b3c6695b8ce4be887d9fedf198e2631c47d77093e427bbdc2ff19fdn/a Quakbot
2023-05-17Gnlbcwvr.jsjs 75203d83c417a2bcd9a5298c46ac9c2befe4e75e7e2c40722c7b8f59a2232c98n/a Quakbot
2023-05-17Toyqjzi.jsjs e700e5befb6cc7960bc6ea4621cca303215be6e09008a3d6c80a8480bd275c9an/a 
2023-05-17Nuzwby.jsjs 2e31b33d33069ac7960028547263395c84546f4f1a37b41a395c2c9ebb484367n/a Quakbot
2023-05-17Ysdeld.jsjs ea6f5962a8dc25a9d8994fb537d644b76a48ad6a8be1715fa1ab9c50ce7a5ef6n/a Quakbot
2023-05-17Jqzhuhkf.jsjs 9ee0b8ccfd307886dd021b84c9e196b269a007c60235a0d869dfe921e65e1b90n/a Quakbot
2023-05-17Gcqkl.jsjs 46c52154bb6b658bc7ad3ea4a93a935917655a3b50db832f4c5365f0f2163266n/a 
2023-05-17Lwulnky.jsjs 34c2213e455c1212bd9ec0677b56c7e6b2eca6ea657f9c7fbe74a9ddb167898cn/a 
2023-05-17Iawqyny.jsjs 5298ca55ed2946e09daf6bf793716f34292367802ba898e7def4e36e88a314afn/a Quakbot
2023-05-17Yesbdr.jsjs 3e485938aae3e04cbd8d299b049d262b0636a973801b0206f440ea77becf1198n/a Quakbot
2023-05-17Uybeylvp.jsjs 5728fb68d728bf47fd2fc836736f745ebb03c624bd7b7e0ac1d966f4ed46a987n/a Quakbot
2023-05-16Dpeg.jsjs e29e68acd422a6c6f0a1917649a1d5d64fed1070d4442bd7ee165c6462430f7dn/a Quakbot
2023-05-16Aonvfwm.jsjs 2a18bdb291b9f32a80358bce963793b53754cb9aaa60a5e4fc605a395cd794d0n/a 
2023-05-16Fcvp.jsjs e4ccbebf7672aca7c67333fb18399175a4b8dcd48aaeb86277513194f108e14bn/a Quakbot
2023-05-16Zbpvbxd.jsjs ce80d7d319da853d0f45895e91f1e752d1a2262c81b9a7d77cda9cf1676312b1n/a Quakbot
2023-05-16Cokgwhuw.jsjs c28b134a34e12bebb584ab67a3a3c53b831800c14b27bd3086f7e4fd32845a12n/a Quakbot
2023-05-16Nvnmeloe.jsjs bf9a09c4e9f2f97fa3e2ca53a0801e83d57585d01e555d8286e82e67b07c4414n/a Quakbot
2023-05-16Ftuig.jsjs 7348fc9bb0d703f634b7277f603e1b27b556406d0c5a1636efce7da3e19c5939n/a Quakbot