URLhaus Database

You are currently viewing the URLhaus database entry for https://colelagroup.com/ui/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633659
URL: https://colelagroup.com/ui/?1
URL Status:Offline
Host: colelagroup.com
Date added:2023-05-16 11:25:46 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:28:06 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 11 hours, 19 minutes Poor (down since 2023-05-18 22:47:30 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qkvnmv.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Pcvvnzxk.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Zlwgnpd.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Xkpdkpz.jsjs 9e4ac7c312849b44186c8e28074843dc580fdcbf0e461d7bbd0b8da3147dd4aan/a 
2023-05-18Okumyajt.jsjs f276da1a81b23b7f647bba9fedb53f4e8df35e0456b09c909184c6c45bcd9d99n/a Quakbot
2023-05-18Zwquhxe.jsjs 8cb9812b4c0409176b2f0770497520692218130496cf0a2a363b4606ce28f506n/a Quakbot
2023-05-18Xoebt.jsjs 176082ec2166a938b76477a4d42d940987b38d787c43628c9e17e75057338dc2Virustotal results 10.17% Quakbot
2023-05-18Lildzzj.jsjs 9d4e35c32d73270df3c5bf64cd693e2933e614075af8f15eeacb3fcd142f8ceeVirustotal results 28.81% Quakbot
2023-05-18Yijwg.jsjs 4aa5f66645ca2168af894232b630df6e88077c51f4fa33cbe2efd094e057fd02n/a 
2023-05-18Edumuj.jsjs 0b5625e5e6c8ca17119f220fef0e5b08313f77e79294375e8b2c57d9bdc47ca9Virustotal results 25.00% 
2023-05-18Tapsy.jsjs 399c7eece18438ba4f325cfc3863d0603d1237732a310fa2124a136ff2a335afn/a Quakbot
2023-05-18Mjjoj.jsjs a2f17ffca655028bf5663349090771ded5e0eac6f65e71d0fc151816a2dc7342Virustotal results 23.73% 
2023-05-18Fyvadl.jsjs c56be3ec9c7d01ede485ea9edabc332ef3aa01f6ab679c4eb6231e1db79db675Virustotal results 23.73% Quakbot
2023-05-17Akfaekd.jsjs 9992a7c1ac03c78d2395f55820f9ac6e7ddca51d747b443183c09f8f2395f2ecn/a Quakbot
2023-05-17Phziqipw.jsjs 798823d6f774c2380137f2e4d5c8a16ea4cec5e96284dfed0891528bdf512376Virustotal results 25.42% Quakbot
2023-05-17Zqjiiso.jsjs 0ae16f66866567a01f4af47c0c7b2e49d1e54eba4e457b2de97f88c48016cedcVirustotal results 30.51% Quakbot
2023-05-17Xdvel.jsjs e34af5d0c51c9f5403ca9b2aad48f7f772322fade0dff21b839a90ac6420cd87Virustotal results 27.59% Quakbot
2023-05-17Ohvcqzq.jsjs b866fb32a73c9c9a6de4c2fa92651d4d8d7f72f0fe66af797867274e8a889e85n/a Quakbot
2023-05-17Lbdo.jsjs 9d9924b0f0e33e1b74db34d25035395c2f29b1c29926ab16bfec2e29f30c8b81n/a Quakbot
2023-05-17Wquewao.jsjs 721e6c8df38e0ab9b2d95989bec2154965d8062721d9c1bb6a8862a1c6e7b073n/a 
2023-05-17Vsywaa.jsjs 290cf6208ce8e66dcd9fae11a86305a58e1e7a98e0f62b49110cc3c8cb406961n/a Quakbot
2023-05-17Vzniqz.jsjs 97e4235a93e03f76ff8a65efc2253d5df4a1492e324a4303c227c073b98c04fdn/a Quakbot
2023-05-17Hbupaf.jsjs b37e40f2634456afd50ad3135c8f475f29f04fedf46243c0a6695f7de8cf2b09n/a Quakbot
2023-05-17Qrevgqx.jsjs 5349bb98c68e800e1d410022feddee90af37cca1cd3934bf2984340d5d04cb17n/a 
2023-05-17Rambu.jsjs 667526d8f5fdf2741a689b416d521dd95f8cc6cacf9a3eb88df24099f161dbfen/a Quakbot
2023-05-17Ptwxq.jsjs 2d069fa763f2685349ad0b30965cdab234731b0742eecae3233bae0898d15bf5n/a Quakbot
2023-05-17Ykmal.jsjs 455fd866f5257f936755a0589511107579a209b465d149ee2c9cd47cb686c1a6n/a 
2023-05-16Hqqrdaso.jsjs eb241de109339d7ffd422c75f6e354defea7891789a9348ef79f7c7608413e16n/a Quakbot
2023-05-16Lhktkybz.jsjs 67ae0072699975f02724437e536d5f581fbf0c95f8dbd8e617e22742d2f91d03n/a Quakbot
2023-05-16Mmzbh.jsjs 5891cc1551dc0201cf5ae698d7b639ef2570c73cb944118a435adec207bd2103n/a Quakbot
2023-05-16Xmztwj.jsjs 5ecf236d178983aef62c95087169f311704eaca967a579ef6b92a7acd9722726n/a Quakbot
2023-05-16Sryifgvu.jsjs c6db6084b358cb47cd9561ffdd767c4da9128d84664e862e66538f76d2107e85n/a Quakbot
2023-05-16Gzjg.jsjs 1ee4408bbf53fc30ab04d8edab87fdfb49af7e02531b2705ab21819341f2ac2an/a Quakbot
2023-05-16Lguolcji.jsjs b471e85d73e0ddb151050e04d50edef4b32275115afff8c325eb72113df19350n/a Quakbot
2023-05-16Spjfn.jsjs 844220122a57b6aadbe3052fe95ebe02ff6bd87a1d101b088f1a70bfc1ee8fb0n/a