URLhaus Database

You are currently viewing the URLhaus database entry for https://selagroagri.com/ntum/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633647
URL: https://selagroagri.com/ntum/?1
URL Status:Offline
Host: selagroagri.com
Date added:2023-05-16 11:25:43 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:27:56 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 9 hours, 49 minutes Poor (down since 2023-05-18 21:17:06 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Kbvnac.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Xxmesks.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Tmajw.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Rfdvx.jsjs 1052736cff0ccbc8f899567c7d037ae380d7134d1157f36f0a66d1386cd00f13n/a 
2023-05-18Hkycmg.jsjs ce5efda576bdfd577cb85bba27c1785787f37d30869878530f7249504d45cf69n/a Quakbot
2023-05-18Vplh.jsjs 6d790992a3828c5f421e6c85ac319d61de4eb5320ff67d91b8e5d4577865de5cn/a 
2023-05-18Wzbjoc.jsjs 294b64c51f30b3884a2067b27a59ddcf4f5c3284a38a7260148eca0e86061a53Virustotal results 25.42% 
2023-05-18Qicweg.jsjs 0b26bdb33f82264e6ee139e028f16f756cf3c276a5c8fdc923aa5d5e2e385872Virustotal results 24.14% Quakbot
2023-05-18Dqbwl.jsjs 2a95cf3c1e69da726dd11f2d5621a546ce89b168fa1cab3506197a63de008d69Virustotal results 11.86% Quakbot
2023-05-18Xmkv.jsjs 7f4b255930c48f8c5845c7ee4b70176ed27fac14ad26798578fbdaf327bc1157n/a Quakbot
2023-05-18Necnxk.jsjs 92541d594f60bdb46e24073e3720e0deb32a8bb5a4409a44b650b790dbeda309n/a Quakbot
2023-05-18Dqptllux.jsjs 11ef57c233cd2baa14c4cfb9579839d381fbdec85d01923f9679f5ed21935f52n/a Quakbot
2023-05-17Pfpag.jsjs 657ba945eb9c34584fcdaaaf316636af2fcddf21425ff248bf2de46d55dc8147n/a Quakbot
2023-05-17Talyobg.jsjs ad227c276250c72ebaf4c13e5d960347009d0762b8c2e696a35b36232e0eeff0Virustotal results 27.12% Quakbot
2023-05-17Shqtiv.jsjs dc776fb044bb27e20a16f383ecdaa44a67be283f4902ddd48f1f6cffd24d036cn/a Quakbot
2023-05-17Rijqvg.jsjs 45a695a6696ee2284f34ef03f76d7192a3829a64f1ae5f5216bfd36983231680n/a Quakbot
2023-05-17Pmfrbw.jsjs 719ff669cd7b0754e787346601124ede6c1238c49809ebd0d6b58a3bf4b5a9bcn/a Quakbot
2023-05-17Wthtez.jsjs 09d00cc1758af4e79c7a38e65ba9555ccb18dcc1f628a22c1d9bd5a337b03d88n/a Quakbot
2023-05-17Xdnmzpio.jsjs 2ef6e700c619c1ace05075497393d8ac827d836ec052de9b6a71a0cdcd343141Virustotal results 24.14% Quakbot
2023-05-17Kfixg.jsjs 0473836cfc335949eae38f3049dd3932d818dc6cbbe8c178f72c74370912d088n/a Quakbot
2023-05-17Zqxzdve.jsjs 0d6511ddb8cf97d9967367c983015cc45c5ea8c7ae68416f28625637be59caabn/a Quakbot
2023-05-17Zhpqaqfu.jsjs 44f7196857e05e0598e098dcb9986198bbb712d9759271552b3b6e0ab27153a3n/a Quakbot
2023-05-17Pyoyufym.jsjs 9c408742ce6e996608f0e70e0823720cd03fd9675632cc0ddb9c9e408bf90be3n/a Quakbot
2023-05-17Gibinnpi.jsjs 87d352efa0669792786cdd6dec07dbffbb70b5ad97988c05dd188e2d1d7ab820n/a Quakbot
2023-05-17Mrtx.jsjs ef4266fbc1c4dca4dc7d8d2fe963b4c00e6d2c07dd353594e330639c035c65c8n/a 
2023-05-17Njfhqi.jsjs f7b10af65c52c2d1e01ceb9fb470fbb53d504c0de035fd60d4f9e8cf0c8af81bn/a Quakbot
2023-05-16Rnvsk.jsjs 9ba769fe35eb557088eb53502a3200898b72ff68c0a3fbc2e0cef453bba71237n/a Quakbot
2023-05-16Dofyn.jsjs ae832bcacb445a5d1f08c79f2936d29f07fb9f1ff13a0bb5343d1e628749412fn/a 
2023-05-16Dvkahtd.jsjs 001d814be6a84cd11cfec344c1a40b488907f3c16e1039056ce4e103ce3afb78n/a Quakbot
2023-05-16Acsjjji.jsjs 1ce57667f3ac7cda59c46dee826dc5b4cb3a45bd6ffd1c5b416f26e53d12ef32n/a Quakbot
2023-05-16Nwfwruaw.jsjs 719ae341142fc043ca17a54b062e1d2fbb3adce25573cc985c0e0e6fefe1713cn/a Quakbot
2023-05-16Rdawaj.jsjs f1a0057b99a9dfa0bd139bb331e00debce3e84caa4ff95def3e2e40ef48df2ebn/a 
2023-05-16Dgryf.jsjs 89b5cb74d6369a3af60ec4a31e33e0759d6c1d57d9ff15a241ffeabec1998606n/a 
2023-05-16Iixvfmao.jsjs d62545dd9117650ccc7f5f126159421ed2f5b5704407cb170f0597cc51b9ff19n/a Quakbot
2023-05-16Xangyhhx.jsjs bcb3b92bbb8792441e5754e6c82f89e297b290d0e6855723924c8b3f5f67cf5cn/a Quakbot