URLhaus Database

You are currently viewing the URLhaus database entry for https://peoplesfinancialfreedom.com/rb/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633685
URL: https://peoplesfinancialfreedom.com/rb/?1
URL Status:Offline
Host: peoplesfinancialfreedom.com
Date added:2023-05-16 11:25:54 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:28:30 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 11 hours, 22 minutes Poor (down since 2023-05-18 22:50:58 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Cbouwm.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Vpxe.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Yumlxwwd.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Kgexiju.jsjs 7f70bd86f6131ed91208cb4f8837b577e488e250f4ea30093ed1d1168e80a9f6n/a 
2023-05-18Cmuecgqf.jsjs 6e988a313f3e3723e109adec17cbf1513010e50c972114a245ebf3ed743e84bdVirustotal results 24.14% Quakbot
2023-05-18Gvtfeke.jsjs 81c46b64d5ec7559ae3287d14b77e2574baf7808d818c8b6f2375da96a544c50Virustotal results 27.12% 
2023-05-18Sozcssvu.jsjs b19665dd5f7dbec102ef5c751b9f86dbe37003d54eb666e3be898351373a0486n/a Quakbot
2023-05-18Zpsrz.jsjs 6b01b5522683c655f6e33fc4ecfa2ef55bae886a543ba306b61dd976a892fe96n/a 
2023-05-18Vrlme.jsjs 2810143d11f9ad7077972f807f2dc04a3f22746f81b7d8365d879e722c0b3551Virustotal results 17.24% Quakbot
2023-05-18Aulg.jsjs 029c7e0d1aaf9b325f8d1adf729b367d04954a895d6c1988c91f700855d91db6n/a Quakbot
2023-05-18Jsuvhb.jsjs 17da932080db984c8594c50184bd0cfde690ed29cc7cd73f3136474e2cae191cVirustotal results 32.20% Quakbot
2023-05-18Ewskpnad.jsjs f15cee857739e493f0b99f7ec002e9fd76dd37b87080807a922a414a5294c989n/a 
2023-05-17Ivgc.jsjs 5ed6c54055399ee6ffdf3adfc06337fb1dfa9ee1a6c1766091b74c1ebe2ebda1Virustotal results 27.59% Quakbot
2023-05-17Gnkryqhe.jsjs 748288dd3065db0c33b5cd484c4347216a3780b90eedc58ea62491f9297a57d7n/a Quakbot
2023-05-17Ebbqea.jsjs 657ba945eb9c34584fcdaaaf316636af2fcddf21425ff248bf2de46d55dc8147n/a Quakbot
2023-05-17Uankyc.jsjs d307232640d2944029109ca441be49052d7c8d24590a54096c256c48e4d7da1an/a Quakbot
2023-05-17Zkwiem.jsjs 962531faf5a4bccd1d88868db9f0b5a79c3073f110ae5e4b9f61d7ea15f8b855n/a Quakbot
2023-05-17Zwkp.jsjs a9f2a0cb2e1331cb0fde62a0318a6e4666f4e283157690f3f7a1059aa73b2f71Virustotal results 30.51% Quakbot
2023-05-17Lpra.jsjs 43f0a123b00abe19f1412b6fff2944e5bf4436a2ba20e3493ba9708ee5088c8bn/a Quakbot
2023-05-17Phxal.jsjs a388bcece7b1bae38b7beb752db64aa65926fbfaba4b9b69a44d5143278cc24cn/a Quakbot
2023-05-17Rkobnohv.jsjs 3ea91b8d79f883fe4499c309db02ec796012a6e11e1a28b19744bec9e0fbbbedn/a Quakbot
2023-05-17Opve.jsjs cd378ebaa81e73387f04111416e2566307712b9b8d1fe490bf9f98a0910ff133n/a Quakbot
2023-05-17Irpqop.jsjs d5185416856f16cb586fd7459724ed86d62c7079f01dbf06c5178a3bb182c9d5n/a Quakbot
2023-05-17Hajv.jsjs a1a8f88fb65beb9386e5921c397ff4eb4aa0f3d197494ce400341d1799f42a70n/a Quakbot
2023-05-17Nwsejc.jsjs c02bbe74a0365b4d3b9e10420175563e8d15826fc0ba6d3e2970d86462d35486n/a Quakbot
2023-05-17Kifmexty.jsjs 9d943b92bc418d3310e2c8b49e515df02f407fe0cc3caf3a7fb3824fd24b6f05n/a Quakbot
2023-05-16Djlf.jsjs 38523caa02f6c9f54bf7c347ae40ec3274951dbd58d7dc1454556b75ca541c94n/a Quakbot
2023-05-16Znghyb.jsjs 2d25f47bf6f78c2da595b88d6662c1ae2e2c05209d197f405cb08852958c4c22n/a Quakbot
2023-05-16Qieej.jsjs 24e6cced96ec6cd85b987185eae7c811cb0f655d0754ff78dccd5e94322d52f2n/a Quakbot
2023-05-16Ufemsb.jsjs 42abfced65e58be08de6f3ee0134e1b0dc47876ea2f84ce48b6ffa96ca36fa2en/a Quakbot
2023-05-16Jbiltk.jsjs c8b71c776e66adfc4dee08eb00470d44407124db443884bbccc7ebde9ca55bb9n/a Quakbot
2023-05-16Hdtmdrwd.jsjs 15ecf62cd86081b5d949b9b02fc95e585c974260cfdac63392410f06f4ab3e7cn/a 
2023-05-16Pssvulb.jsjs a31db4c3e64b2332bba471b91c4227e7b41cf02bf53bc2b2e0a8651325e1cbf3n/a