URLhaus Database

You are currently viewing the URLhaus database entry for https://g-cobro.com/lai/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633681
URL: https://g-cobro.com/lai/?1
URL Status:Offline
Host: g-cobro.com
Date added:2023-05-16 11:25:53 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:28:25 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 10 hours, 14 minutes Poor (down since 2023-05-18 21:42:26 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Teprmqm.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Zufnbr.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Fspxaiq.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Gdoxih.jsjs ff638559e4763e44ffd732b9cadf3815b6c43fe352a978b7dfa62e3a180411een/a 
2023-05-18Qeimtmz.jsjs c0b055c045ed06b66e9593d4cef1c8ca4450d0224401d8dbceb904fbe942f4dan/a 
2023-05-18Vrlk.jsjs e097747aa43ca0c5787d98ebdab3ab67fda12444d287a4a0702a670f0b2494d3Virustotal results 11.86% Quakbot
2023-05-18Szxgcwpu.jsjs 07cd66f1c775da49daf409f335ec5d0189ba991d2e66c33b01708efe1934e0dfVirustotal results 27.12% Quakbot
2023-05-18Jzwgli.jsjs 47f14a8b9c04f43e700eff818ff6490f28ae0bcba08118d1af9f0b06c96779a1Virustotal results 29.31% 
2023-05-18Vwrskzq.jsjs 576d767be1b5ee880a56263521aef9366435f9ff583a68aebc426d7da2c02e2aVirustotal results 30.51% Quakbot
2023-05-18Qbog.jsjs 992ec3c1bccb3793a6ae36e909056122ef9e442c16c17bcf9d771c90b85ee980Virustotal results 22.00% Quakbot
2023-05-18Vdsptdod.jsjs f95ae26c9bf7ecb6970afb88bfa12c71eafd8b35160d2c1658e57d36ea915477Virustotal results 29.31% Quakbot
2023-05-18Ubsjwy.jsjs 5b081d8987954ca182f1f9c83eb5c24851ef6647e29f84c5fde150d826531e53Virustotal results 26.32% 
2023-05-18Nuic.jsjs 3657123d41437d5c2c4b48b03e14153b367398907ae10d30021c974941a5b64cVirustotal results 32.20% Quakbot
2023-05-17Ggaobqkg.jsjs 2e6fa76c0870d4318d71a8defd95759f831cb88397931327f00478d853bc9525n/a Quakbot
2023-05-17Ysjgueqr.jsjs f6d73eed4ee4cb252294f53568ea49c055a4a65267b79e8491ace852655d5575Virustotal results 27.59% Quakbot
2023-05-17Pxrkkxy.jsjs 64dbefc6ce8b2caf9b441a36490ebed30319eed28e49ddf95d43659494906f10n/a Quakbot
2023-05-17Nwjhvys.jsjs 5eecbea9208745932f291b3156e7036997e4b1e93f7bb53a270cae7c125aa079n/a Quakbot
2023-05-17Zxbv.jsjs 74e7f951fe5dcd84fa5c570a1b2e27991662022a85a90f8f38cff80d462e8541n/a 
2023-05-17Yypb.jsjs b5e43b4ccd0107bcf4e8ce081135f2adb345ba3df9a4df5637d3cd9e08b43ba8n/a Quakbot
2023-05-17Hmcnnpf.jsjs dc776fb044bb27e20a16f383ecdaa44a67be283f4902ddd48f1f6cffd24d036cn/a Quakbot
2023-05-17Dmlcg.jsjs d1c65ec47cc051ecc7f4b0e9ba62a68a79fdff595d2aa99f08a408dd8b03db57n/a 
2023-05-17Fmfseg.jsjs 2d0b8a32d785b0a6194b2ae17147461a818fc353fc6d90cdcce2645c06fb8f9en/a Quakbot
2023-05-17Tuspbqy.jsjs c8a0490968bad503d5e24269abf29e2bed035412bf03968d43bf06bf81656c0fn/a Quakbot
2023-05-17Jixcg.jsjs a81e6a1bdf9abbe924c256e661b4676de717da32ccdaeffc13998fe3eb868320n/a Quakbot
2023-05-17Qreve.jsjs b3a8bbd84326fa58f6c90d1ad0148a0e81a7238006bf595c009b7ea6b74df2bcn/a 
2023-05-17Akkxall.jsjs ae6b7a8d12ede4bacf926da5faa6d09e69d3abbd9664d8156a02c7a4d4643150n/a 
2023-05-16Jofm.jsjs 1a8fcf9bab58084dcc060246a251f405cda29e9ff581e7f47239072abb1f8023n/a Quakbot
2023-05-16Ihabsks.jsjs 97fc76f7d82895618e7c71dac3bdb9baa6f511582ca88bf88ad2812a68aae028n/a Quakbot
2023-05-16Mibzlw.jsjs 6d6b6849afaf440ba8521c301064b61f02effc2b3cf9f56af231cb4e7a6bbaf7n/a Quakbot
2023-05-16Bzqb.jsjs 0ad3aaeb5e4210cc0f31ce114cdf2219ebd70890e580bfa0c6ab3815d64e7371n/a Quakbot
2023-05-16Gffjhi.jsjs 723ef95b47a7b5d24244b963862f28efa1e53db9c1420a87458673a3b71244bdn/a Quakbot
2023-05-16Exbcgka.jsjs a5887408a857be831e001d2502f204c746cf083e991d188283887d06a68a844an/a Quakbot
2023-05-16Ybjyb.jsjs 7b2775d444692c8c74b81e9cd1fbeab41740c45558e1aa95014d6a90b43be88cn/a Quakbot
2023-05-16Vurjn.jsjs 737fd3e4fca7253f532e1a4f785905409b58f8f7a08efab3ad20ecbe4d88e6b2n/a Quakbot
2023-05-16Valyc.jsjs 5b3c2af229038cd4f8333f690190047e1fdad7b9fe9d1121e0cb9bbd444c667bn/a Quakbot