URLhaus Database

You are currently viewing the URLhaus database entry for https://book-of-spells.com/eumc/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633641
URL: https://book-of-spells.com/eumc/?1
URL Status:Offline
Host: book-of-spells.com
Date added:2023-05-16 11:25:41 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:27:52 UTC to abuse{at}namecheap[dot]com)
Takedown time:2 days, 11 hours, 28 minutes Poor (down since 2023-05-18 22:56:31 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Fjkwoza.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Hrzted.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Ufta.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Nznl.jsjs ce77f8be19286593340f338e5e2ce6bcb6737053cf600ba09676d32f607ae3aen/a 
2023-05-18Mnzvozmc.jsjs b64790ef2bb214bf0fea83cb0aff305cd66dd38f065ab3cc62b9ddf5d3570eecVirustotal results 23.73% Quakbot
2023-05-18Xnrz.jsjs 649828b67fb96d9addc5f4c9518dfd03c7eaef5dfe3afd081708297f2d160360Virustotal results 25.42% Quakbot
2023-05-18Mqsrlps.jsjs 654d79d5b714216fcec5efd06082250b58afb76155c0be229ba139acd68d0797Virustotal results 25.86% 
2023-05-18Fqhy.jsjs de40c651da56945e6aa4f1adecf9ca842f4b2c630f3e1ad45c2c02952d4578c7n/a Quakbot
2023-05-18Qojsfwu.jsjs b5e43b4ccd0107bcf4e8ce081135f2adb345ba3df9a4df5637d3cd9e08b43ba8Virustotal results 21.15% Quakbot
2023-05-18Vtpeavz.jsjs d772a62298f946a1a964db9c0e6aa23473d6590e013fb3056502ad74b75a046fn/a Quakbot
2023-05-18Lzblbdu.jsjs f517f6e7dd7c0f029a72fe25803ac2d5c54c7abcc8e576fbf95cbe6a87759540Virustotal results 28.81% Quakbot
2023-05-18Mcoryif.jsjs 80f6fd82b28ccaacb151e0447865a17ab4711eefd8ab38eb96bff981a7077a9eVirustotal results 28.81% 
2023-05-18Jlhyyumh.jsjs 1c8c07d6d5454652a85d1673775e071cb4068ca92c83d2e45e4cf830d85e56b7n/a Quakbot
2023-05-17Obsscv.jsjs 32710b418e9ddc449d0548590b62ac23975ad6efba53cc55cb1551326e182cb9Virustotal results 30.36% Quakbot
2023-05-17Obvgkw.jsjs 8f360ef4554f315b708ec9a47229a77553d9764d491faaae0340e0e552551077Virustotal results 27.12% 
2023-05-17Rsohtxao.jsjs 7f5bfd748f09cddad1977aabe48a77b4aa3281b4bc9ac685ca0e53226b92c107n/a Quakbot
2023-05-17Xlchbzgx.jsjs ba4eb74cda0088a1269ede2dd12d974109f7b392ff522322070233d302cb3d01n/a Quakbot
2023-05-17Hudq.jsjs 569b94ae6e9101918add0cbef52c7d0516b8faf8e79f3273d7d102982c544c18Virustotal results 22.41% Quakbot
2023-05-17Xvrnnzmx.jsjs 3d234411a958948cb4805e18eb29cd95fbd93086ffda9ed636c6d322523b5e80n/a Quakbot
2023-05-17Fbmdrez.jsjs 07d1842292aa2619ebfbb551eff5580fb24f945283f3de4298dc06f9493b6b20n/a 
2023-05-17Eujnxq.jsjs 090a55e29be295f623c125ac567236b4d6e112a890fe2b0f43593d8ed78d3daen/a Quakbot
2023-05-17Mjugw.jsjs c3d1ebe98c1539ba8164629ed814684e60f7781429cac4c32bd0426ba8bd6ac5n/a Quakbot
2023-05-17Jluxlxig.jsjs c84ca1d4012c6ce04e80a41a6a7016abf4b395bb85ab670e4d06ef0b02a94b6an/a Quakbot
2023-05-17Zislhz.jsjs e722b9ef6b9990adbefaef227516ccf5f985f2c6dabb7e982bf52c3f85680237n/a Quakbot
2023-05-17Dcwp.jsjs 7d34b9f353414703714bd54d97da998ed7631abc87b32a0767be646cc4edea23n/a 
2023-05-17Ijlr.jsjs cc882afd2e57e09fbaf7aa1d82fd84119f11ce178e2dc99ca9f8364fb03baedcn/a Quakbot
2023-05-17Cysxq.jsjs a890b40ab4801b230dbfdf82e41be32c368010d0385e14baa3060c2f75ae2214n/a Quakbot
2023-05-16Grfjyjgc.jsjs b4889e0b21bfa4d2919102c7063f8a39382a6ec10c36051e3611012cacea26e9n/a Quakbot
2023-05-16Znumwgt.jsjs c79f55a17d459936aec242a0ec28c5b0503d41b4c2a66ebc79324fa34b89dfeen/a Quakbot
2023-05-16Lrbqxvow.jsjs a825a0a88075895bb87e8b39af1f262ec8beda8134c2a464a3d85219c3b9c21fn/a Quakbot
2023-05-16Ephobjxj.jsjs 6533cc68bb8d7691f4a9c0b66ddb76f99bf2ffabf3724b0cf55917508ac26720n/a Quakbot
2023-05-16Xlsnh.jsjs f786df00899a4add4efcc0de66aa5ad77966c0d6a3f37d9b8c0560b94af36d15n/a Quakbot
2023-05-16Kmek.jsjs 64f6560de4fb71d77759e1a770557b164a4ec925ebc9a99d13d71e3caf858438n/a Quakbot
2023-05-16Ntiik.jsjs 5eb9fcbb44c51f8f382ed4021a2cc3a365a3f4d73f49241f667a5eed8cd47c91n/a Quakbot
2023-05-16Wopluz.jsjs 974cb2836267e34cd46007f171554e1611840f1193a07e303a08158980ecfee1n/a