URLhaus Database

You are currently viewing the URLhaus database entry for https://kee2marketing.com/ieu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633644
URL: https://kee2marketing.com/ieu/?1
URL Status:Offline
Host: kee2marketing.com
Date added:2023-05-16 11:25:42 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:27:32 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:2 days, 10 hours, 7 minutes Poor (down since 2023-05-18 21:34:47 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Zfbfyss.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Atqrlciv.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Fcxxif.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Chdzwct.jsjs 21ec8c04c7149904b945012c8b17313778c7d7dcb69cbb09933eb303a7fc4d38n/a 
2023-05-18Qxtoezj.jsjs f4454d45458f3aaadcdfc328fc4107a6c670b1c0e04df1d476ca56e831b83818Virustotal results 27.12% Quakbot
2023-05-18Peusksvj.jsjs a64cebdd853596ce95beeb112b9dfab6eab26ff09b77eaad1c909cb1b6cff48an/a Quakbot
2023-05-18Hmybtx.jsjs 1e96a7079b653386193018082948ee18ee1ca517dd96395eb46b4d5e30507b87Virustotal results 30.51% Quakbot
2023-05-18Xegkwqs.jsjs a5ad0d19dd6ae50f16dc5be1921c43a887aba5ab8dae04acbea417a5cd62d61cVirustotal results 26.32% Quakbot
2023-05-18Rjceb.jsjs 5b2d175b18348c26ef8ad20f51fdeb4aa6ab4076aa57cc05caa3cc8772385077Virustotal results 25.86% 
2023-05-18Jcje.jsjs 5089e9979f6a45bba9ac940e1e725185230875623b2242cad8dfcf968141f073n/a Quakbot
2023-05-18Irwjxwww.jsjs 5e2610a338e8ef5c3c882966366fdd36d988d79233ad84071b96fe04a7ea18cbVirustotal results 30.51% Quakbot
2023-05-17Pwxrrnva.jsjs 20bd75aa446aa0b87c0d7042cd6119cf26dee2dedc5fe401477ada73a6c84e1eVirustotal results 22.81% Quakbot
2023-05-17Iqbfpvv.jsjs fdf950ea03d008fe87c7f897e464c152d19d8f830013223033ceb1852f37ef5en/a Quakbot
2023-05-17Ocwnqw.jsjs 08b43f87f3dd81d9be92cb99ab4547399f67348b7ffe33011b49947b98a44046n/a Quakbot
2023-05-17Rwnh.jsjs e34af5d0c51c9f5403ca9b2aad48f7f772322fade0dff21b839a90ac6420cd87n/a Quakbot
2023-05-17Gszpq.jsjs 60ac270ffa4c64db98f324558c25656b20d8d9f301831100a0094e2356e9d4f7n/a 
2023-05-17Ynwzsapj.jsjs 0945468f5418041d46192ff3915965bea4c8393b6191f0f65cb0bd94a1ca06b7n/a Quakbot
2023-05-17Jruxdhh.jsjs 2a23a37e5c80707e77f895078ba793a1712d2a4c490ed9a52ef68b7d29b992d2n/a Quakbot
2023-05-17Wjlbjaq.jsjs 4b63d9d0cca2facc0ee1dacff2f9a7b8166b0c21785571644ea46ca69d9ff4efn/a 
2023-05-17Djcqxn.jsjs 897a26c0d5208cba3ca228cbbba1d52e310988a00bad249a7ef0b52ba57d3a0an/a Quakbot
2023-05-17Zchqtw.jsjs 2699292ee1ab9ed22ddfab9a8f94db6632338ba1c8bdb7f757294d8a3e69c448n/a Quakbot
2023-05-16Hdtvf.jsjs 32a669b8c738b1b6c9283422a24131842a97a5bba1a7e68a254339f85bb1187an/a Quakbot
2023-05-16Cauiwb.jsjs f4ec0fb1a2e9a7f6592298165ab5d836fac7d57bcae787f5a285b798804bcb66n/a 
2023-05-16Ddplguya.jsjs 77a97e10298eb2f285778653d60980f9d6459a10da0dbb560a14c3ae550efb80n/a Quakbot
2023-05-16Zsdwb.jsjs 7827ffc11d064bfc7ebd4c8aed1e27c77baa271ab4446a6a1de41ee2bc18fe98n/a Quakbot
2023-05-16Rzploac.jsjs 2cc60bbadfc6e228ab5b713e32748c895cce01c63fce60624d35f02264d4da9cn/a 
2023-05-16Xxlo.jsjs bb179e1eef852a26a0142fe441fc505b8374e3fac318c3857891ed4bb05bdbddn/a 
2023-05-16Grsdjtex.jsjs 1cf6c12ab7e8825226e0df2c7af9b93594ef88f118fe8b9ea10795480f1a0a3bn/a Quakbot