URLhaus Database

You are currently viewing the URLhaus database entry for https://arcollectionusa.com/ttsn/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633702
URL: https://arcollectionusa.com/ttsn/?1
URL Status:Offline
Host: arcollectionusa.com
Date added:2023-05-16 11:25:58 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:28:43 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 10 hours, 14 minutes Poor (down since 2023-05-18 21:42:49 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uewqthnl.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Xymbeued.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Kbmjvqv.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Hqvrrdwm.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Ncdszcq.jsjs 8af159f13d1f3f3a4910460474e905ac155535ed434cc3d1d34b828512579d14n/a 
2023-05-18Fxav.jsjs 494e69eca209ceb575b3ad74ff164605bc99c57a7621108280f95412b64e0becn/a Quakbot
2023-05-18Utqzly.jsjs 1f4c2a4e8c95bab7ff916109a3978612cf0969f85e9f00ded884776dda11eefbn/a 
2023-05-18Vjuv.jsjs e83bd9c4b21fcd0dac063c512259b7310762d0f7b923cba778206403e5314398n/a Quakbot
2023-05-18Okafoe.jsjs 2a38d5dd759f5e13e433429b8fbed42e9b1fa7de9f671bf87d0739862847c16aVirustotal results 26.67%Quakbot
2023-05-18Xtfmv.jsjs af020f4121ed33dba057c101c7d8fb714a2c96c883601c63acf7dc505818a5a6Virustotal results 27.12% Quakbot
2023-05-18Dmvllj.jsjs 8f29c702a43f99c1cfc18167ff61035ac4068757aba92e0eb5e9dde5ad72a0cdVirustotal results 31.03% Quakbot
2023-05-18Xdgzjqtl.jsjs ed175d3585ab2d387e6c4a9420d8aa055d62ef6670fbe83a0f66d5bfaf943a92n/a Quakbot
2023-05-18Baoi.jsjs 345e76a5091b5ecf319a57a8901fc203f48dae4dcc62b70fdc4d1e542d1a1f46Virustotal results 30.51% Quakbot
2023-05-17Jhgoypp.jsjs 5848de38e1e0698b0e24ebe9bf6c45ef062f0f7d7dd7444e4a32d6731d5802aeVirustotal results 33.90% Quakbot
2023-05-17Laazqxu.jsjs f4454d45458f3aaadcdfc328fc4107a6c670b1c0e04df1d476ca56e831b83818Virustotal results 27.12% Quakbot
2023-05-17Udak.jsjs 7217ae2adc382459d109d0ca1135074318d85578de92f3c231dd520402b6d647Virustotal results 27.12% Quakbot
2023-05-17Zzvuvmw.jsjs c936abc12d461d92641e807274f5df2fb3c02f2e568920845092ed9547299bafVirustotal results 8.47% 
2023-05-17Rgzxsnt.jsjs 8f547a495bc6e319219b5db2491f70ce4792f76b7770226d37be2b28fa5f79ceVirustotal results 27.59% Quakbot
2023-05-17Cnxl.jsjs 27d3fa3ffa307f97bc3047f15898d338734929484e224f43ab8740c710601a78n/a Quakbot
2023-05-17Nsbwakz.jsjs 16fe8055701bf9e829e70c4811b31fc75aec4d03582697ab493fd530e84ac6cdn/a Quakbot
2023-05-17Zptgid.jsjs 4199aea159f7829cacce2dcf979b07474ecef8f9e346c83817680cf1cccae1b3n/a Quakbot
2023-05-17Rlwg.jsjs 50995ded2a5930353fdd8e9881186aa8086a135e1062078cc3b625ac3a7a5b53n/a Quakbot
2023-05-17Zycoty.jsjs 94b70a7ec717292834dd7045571c6bd5118bf1c7be72f5b919f842821d7d79c1n/a Quakbot
2023-05-17Gsowor.jsjs 6f3713a008ae555912b14694bc22e249706e8f8641ec95f625b4de130c4d2bd2n/a Quakbot
2023-05-17Vdjfesc.jsjs 5786f4fdef3d05b299846e0d1f499db1e4f756fb1d210c36c19507754d891f31n/a 
2023-05-17Vdsrzyti.jsjs 98981a04e5a4ce8c09ff4b4e772bc323bc52f39363305f200dc1d96297b3201dn/a Quakbot
2023-05-17Gwyfefco.jsjs 92db81a408ac7fff532d373b708fb4dddde6d7b086790eb918ed2699171c4b1en/a Quakbot
2023-05-17Ouaw.jsjs 7ce5b923a7e063949a5a0c4e08c8b512fab7ae4eb0b8c0cd6849a27e25fe2cfcn/a 
2023-05-16Gmfzzhu.jsjs 036cedbb75fc2eb5b7a77c1842eeb0b364c6c0bef17f703f716f3fc463766d72n/a Quakbot
2023-05-16Xolpi.jsjs 43f756f9e65159dfdadd151bd87f6114ece16d3206157b342efcdd1af7d0d4afn/a Quakbot
2023-05-16Mcgen.jsjs 7453aca7803c6a8811c57fee42e6d7e057f4629cfec099e1be46e8d4a9b485c2n/a 
2023-05-16Iwdy.jsjs 32c8825a5dc39e042ef7f7ad425ceaada693257dc3a80cc7712754bb584a25bfn/a Quakbot
2023-05-16Qnbwb.jsjs 4418543e53c7ef648bb496c289b6a606bedbc960ac20d312c402d1fa8388928fn/a Quakbot
2023-05-16Ssstpfm.jsjs a5626625809267ad35bd4e0813e0010e2614d74e5b3f49216460365ddb8055a5n/a Quakbot
2023-05-16Dntm.jsjs 9d0ab67c6e5143b0121124935ec3adb5d9e2e60c2d90a7e991d519542d6df7f9n/a Quakbot
2023-05-16Ehdixihp.jsjs 71d5e521439356bde93d51f2db9c7a9d246e32352aa6f8a258be8305ad949182n/a Quakbot