URLhaus Database

You are currently viewing the URLhaus database entry for https://bestbudcpa.com/ual/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633664
URL: https://bestbudcpa.com/ual/?1
URL Status:Offline
Host: bestbudcpa.com
Date added:2023-05-16 11:25:48 UTC
Last online:2023-09-27 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116414 created on 2023-05-16 11:26:13 UTC)
Takedown time:4 months, 13 days, 15 hours, 46 minutes Bad (down since 2023-09-27 03:12:42 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-11n/aunknown 49a73590a34ad72e005c32bb3dfbf0b6554b1f80cee252791ac42d146b2f5bc7n/a 
2023-05-18Zcprrt.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Uwikob.jsjs a323aabc78b895eabf807a1f247d078912b321a622e358fe3b4a7007ba5349fen/a 
2023-05-18Ekxgsiu.jsjs fc087bbfa79c07ccc635f8a6fd0b89dea00fce47f2c8fdd18e9a29c72d8a3bd0Virustotal results 25.42% Quakbot
2023-05-18Gcnnfrsk.jsjs 5b03a98354c24b442061c45caca4e261ba88fe1d68187bd4c44f84773d562a6dVirustotal results 22.64% Quakbot
2023-05-18Eekxec.jsjs 45a695a6696ee2284f34ef03f76d7192a3829a64f1ae5f5216bfd36983231680Virustotal results 26.67% Quakbot
2023-05-18Airkxwo.jsjs e8a4b575211295a78e536c4a374d5538f24470f6036d3a1e5ab52f149b6a5683n/a Quakbot
2023-05-18Uypeangn.jsjs e8cadb2bfe88e91c6f0a88fbfa3c83c7cce944155ffde2920ad925df8ba77f75Virustotal results 24.56% 
2023-05-18Gyee.jsjs a357a8a9b62674cff6660b76659f4cd36ccd979d44937371bde57235d81c392en/a Quakbot
2023-05-18Vdgikrvt.jsjs 494e69eca209ceb575b3ad74ff164605bc99c57a7621108280f95412b64e0becn/a Quakbot
2023-05-18Hlxzbect.jsjs 2ae770725a34857b3a2ff3821341d0b0363c401b4588d1bd1ce75048f2b83a18Virustotal results 24.56% Quakbot
2023-05-18Rizttq.jsjs 935d2fea6488c7d2c6ec2b528f43f43c49b96750bbf21401284b5c42710e8c75n/a Quakbot
2023-05-17Zrypbpdi.jsjs ec6f55b9c56d3dead8b8490dfbbcccadcdfef62b7d67c671b8d0ee9620f4b74fVirustotal results 16.95% 
2023-05-17Rmkrr.jsjs 69d10bf1c18cc7df540de106a1056c5af79f8b60f1ffae762d06532cc84375d8n/a Quakbot
2023-05-17Becgxc.jsjs 7524d906b4d42ae7fd1e5e15cb503e8b54fdc1afa702a0b4e4c5f1d6f99edd1bVirustotal results 30.51% Quakbot
2023-05-17Yibwpztm.jsjs 8f360ef4554f315b708ec9a47229a77553d9764d491faaae0340e0e552551077Virustotal results 27.12% 
2023-05-17Dhbhlv.jsjs 2810143d11f9ad7077972f807f2dc04a3f22746f81b7d8365d879e722c0b3551Virustotal results 17.24% Quakbot
2023-05-17Ocftgblm.jsjs 9162c26ac66cb673664c91b6a22e788a008db7c2bd2b4a9b7788a47fe85f33eeVirustotal results 28.57% Quakbot
2023-05-17Ixfs.jsjs 8475cb42b6b2c974e37378cf11491570a83f194a37e5ebbc50add4a5677d6d72n/a 
2023-05-17Xpbiqlp.jsjs 84dc4956b015f86429521cf8a9aab72e01b3d3f14b77f769b37d48f3bbcbde7dn/a Quakbot
2023-05-17Sxubii.jsjs 2c6dc5cee8d581c5e1a536b1ca5d06773bd267d774c8a96988cb315cf08471a7n/a Quakbot
2023-05-17Pbmxe.jsjs 04a2fe2acff211db737fdb5ca22ee964b23e3552744d4da128eedc0f8bdbb8b6n/a Quakbot
2023-05-17Jdey.jsjs eb7b725f9b066fda9d9bfca599b2983ef8e1fa159bb53faf82dcebbd28691154n/a Quakbot
2023-05-17Hgdse.jsjs 762222d756dccd166d8d81620a4a530ca48654906c00668a4e5e0d61675666c5n/a Quakbot
2023-05-17Taon.jsjs adf8530a651b4bb850d91e5569d52c49eb741eed22d522299c3c6d883e521f3fn/a Quakbot
2023-05-17Ieogz.jsjs e275d0ac91f82b23a8c79bee2af572918e9d8fe1b7ccb7e9b79e9f2c01bee0c6n/a Quakbot
2023-05-16Cfgcf.jsjs acfb2861682a3d43d6d87458517eb0b5793dd6fd020b5eafd874fc0ba15e5aa0n/a Quakbot
2023-05-16Zrnzk.jsjs ef535565589a37c61f435c4e7f3b664b5c8786a63893bdb6f646a812d74f8738n/a Quakbot
2023-05-16Lliyxchn.jsjs 2dadb7f157d439e0c8a96386010b9eb5f5a77a15bd48b2f9fce4a28dc254943en/a Quakbot
2023-05-16Hcrt.jsjs 5eadaaa5755a26200528f473e353a417f45b7e6f8eb8b6de269e0dde2ee3e2edn/a Quakbot
2023-05-16Tlweszfy.jsjs 13977ecad13f044c521397fd8e01d6f356f4b55efef7354f9cde6452823c6b6fn/a 
2023-05-16Bxnoiy.jsjs 5e1bb9a590aab338ae281bc109d9a2b73a6a2fbac29a16f7b8002ea9f953d3fcn/a Quakbot
2023-05-16Hvbvfcj.jsjs f1f5133e8c710f692f01c54654eee2562c0e8caec0c9e532b6770b277cb976c4n/a Quakbot
2023-05-16Rbthu.jsjs 0c59071f96c3924278871d9f1ae3ac2a5abd0d8ab615dac10d9abadcbfd214c8n/a Quakbot