URLhaus Database

You are currently viewing the URLhaus database entry for https://expressdailycare.com/ant/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633711
URL: https://expressdailycare.com/ant/?1
URL Status:Offline
Host: expressdailycare.com
Date added:2023-05-16 11:26:01 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:28:50 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 10 hours, 0 minutes Poor (down since 2023-05-18 21:29:15 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Hscivusu.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Yujnq.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Apxm.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Lpeynbei.jsjs 2d346d1971cb1099006b43b638240635c2451564a6d28639b10226cdcd6e9156n/a 
2023-05-18Tgxe.jsjs e0a76560e4dfa1a02a0ed9070737950e644f0b851388f7a580a8c384ba1ae3aaVirustotal results 28.81% 
2023-05-18Tgmto.jsjs 81f0fe1ef9b350d79e5c368c2f73deec42c5a379bfbbe52f88c1c79ee481b5e9Virustotal results 11.86% 
2023-05-18Epdaa.jsjs 5526b208f51ee2b6adbf6b588401d5c1e058973988c16897fef27cdf25f2a51an/a Quakbot
2023-05-18Iboksvu.jsjs 38158794f34f920ddf3cc1bd5048a2d8be22b550ea27c09a0c746d59e22b3fc6Virustotal results 32.20% Quakbot
2023-05-18Vflb.jsjs 7aabd12a63a4289e6a5f5fc62d866ed2ade8e917a6f2d203bdfd37c0f87ab265n/a Quakbot
2023-05-18Bcgzrhy.jsjs 320db1d64ed5a7a4ed401ebf9861a9776e220be46c59f4113bebf562f9e506f3n/a 
2023-05-18Sgsxvulm.jsjs ced3c62c0b0eb34cebf34dbcc0ee8a52ffec9388cc383952b09c7aa421199a79n/a Quakbot
2023-05-18Fdsngw.jsjs d4d054686a5e084363a71c69d138897e7b35fe3a4008cdd377ef2a2121799d11n/a Quakbot
2023-05-17Qyaow.jsjs e8cadb2bfe88e91c6f0a88fbfa3c83c7cce944155ffde2920ad925df8ba77f75Virustotal results 24.56% 
2023-05-17Nvhlrbd.jsjs 928455b0e6b3a04da2d4fc9cc17de42c52ae2a640937dcbc9a048f76050c138eVirustotal results 28.30% Quakbot
2023-05-17Byyk.jsjs bbb3857a4a55979cb62365c0f64de4c52d6dfb99575872792f1875a6b7d5afd9n/a Quakbot
2023-05-17Akdqc.jsjs b45fa98328f6170801cd88be88f4ac670f2266e2ed383e78f37fdd5d860dc695Virustotal results 30.51% Quakbot
2023-05-17Qiposc.jsjs 397ed6d5f113de3b5a638878e1ab22bb58f5fb493aaef92441db571bcb4c81b5n/a 
2023-05-17Uydj.jsjs ca9502bdc52560b18884b4483fd8adca417142d736bc92b2039511c11483e4f0n/a 
2023-05-17Zyqbipku.jsjs 093448f742b4cf2ae4f1735cf8412dc6962c1687753b3e189e8e877b84705acdn/a Quakbot
2023-05-17Kjzl.jsjs d79ca6765f2c1ead848162593ff3e8cee4416ee7524f281114cb76d41f913538n/a Quakbot
2023-05-17Miphhyju.jsjs bf770b5e4783bde5e8a5f063a36bab4542ad60d5f9decbb769f4667782b2f317n/a Quakbot
2023-05-17Yinxgfuz.jsjs 3fe578eae8f9834e251d8006fc0a7d4b25d7e9a6a1ac7191a198e2594f8a04a0n/a 
2023-05-17Kucnifl.jsjs a3943f3d180343da6b568c0c2a5315d846c4008aa9fd5ba13d80542ae9b35b94n/a 
2023-05-17Uuwidky.jsjs 431a8bf8762b32cee2e0cf8ebbf5f0fd7158e6b2b40f7c487aa62c104334d253n/a Quakbot
2023-05-17Nkzrf.jsjs 4459b4b2cddb3a68ca193ca050e54afe248a6aeb6064d0bb18588be8826be9bbn/a Quakbot
2023-05-17Eaqgpoo.jsjs d550f7a54f5d9d3046814e8bd00c48572f52703341e82cf01b461af804fe1f2cn/a Quakbot
2023-05-16Xytrn.jsjs 838a8a417b8bfe76751ec849618917c26a147fdbf9b759c6d53136a171948b5fn/a Quakbot
2023-05-16Ucwbz.jsjs 2301084dc1c3f9587b89a664c0a9df5f5762011cbe2e4245fd810fa585bd399en/a Quakbot
2023-05-16Reyxz.jsjs eb233b8be90108e9e6108a4d70e05c6ac1930e475b80dadb3fbaafb77e180cccn/a 
2023-05-16Xnrsftij.jsjs af270f894abb701c81141bb21a40b72a92ec9f767d90b139467f26a80e34ac09n/a Quakbot
2023-05-16Bjsg.jsjs 5b188baf847f3f023c1170041e19110037004af20b5ab2c1745dd38a6cf0d068n/a Quakbot
2023-05-16Ryyj.jsjs a55345d43291b70b44e966e49ab332f24fe1c095d2a3dec83b10e5580da98307n/a Quakbot
2023-05-16Eravha.jsjs 0ed74d6b24e0ce19c2fdd11af64b4714bc1737d87e42d9bcf1564056330926b2n/a Quakbot
2023-05-16Ffrlkqyu.jsjs cbfafdef59544db25656a588f9e217517602b1b4b30e53ae7bb5ebc17091b96cn/a