URLhaus Database

You are currently viewing the URLhaus database entry for https://rossandmorrison.com/mldu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633727
URL: https://rossandmorrison.com/mldu/?1
URL Status:Offline
Host: rossandmorrison.com
Date added:2023-05-16 11:26:06 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:29:04 UTC to abuse{at}hostpapasupport[dot]com,net-abuse{at}hostpapa[dot]com)
Takedown time:2 days, 9 hours, 35 minutes Poor (down since 2023-05-18 21:04:35 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bposc.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Kszzm.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Rzciut.jsjs 0f9975b760f5de0e55d98fc60e72802bcdbd786e193f73266f190799bbeb2fe6n/a 
2023-05-18Gprzbffz.jsjs 39ac88782d43b40c56cd7245203211f747e986908f13072c8d6d6caede0ef79eVirustotal results 30.51% 
2023-05-18Uesmgoug.jsjs 1ef243d363359aa7c5d8ab0a55ffa52a9302f63a3750df5b8408c99641bb9ab9Virustotal results 27.12% Quakbot
2023-05-18Hsgigbwx.jsjs 971bd37b998eb4ec97738fb7c5f921bcf1fe5ca6625167693aff2cb06a748e7bVirustotal results 27.59% Quakbot
2023-05-18Nerhull.jsjs ced3c62c0b0eb34cebf34dbcc0ee8a52ffec9388cc383952b09c7aa421199a79n/a Quakbot
2023-05-18Xdawdtbj.jsjs e3086e125c0def5547c4247942eaf8cdeb0e4e581562f9cef5e20b6978761c61Virustotal results 32.76% Quakbot
2023-05-18Bnaaz.jsjs 003a7f907bd61ac3b7c2a9dddb1bcf8822364010b01853af755fca54c3f2fd80n/a Quakbot
2023-05-18Tzningud.jsjs 16e669d4d5391d00940846a4f52891c84d175cd3dabd4f776ef0b2b352c4f2c2n/a Quakbot
2023-05-18Xdxffqt.jsjs 819c3375d47e95f26e1466039e2ff5a096837d0761bed7564c2366b094c8895bn/a 
2023-05-17Ppnwlm.jsjs 8319c01bce9a24d28eeb4e926938d179f37c880ab2aaa26290056ff5089ceae2Virustotal results 27.12% Quakbot
2023-05-17Nzxtu.jsjs ca42f27ebd7d4d5472c9652e26b5cd7d9f089e838ea85a8ac5f1c51b37e83e30n/a Quakbot
2023-05-17Alehalr.jsjs ed4b4009ba340ee9369058f34b9f50d2cb0057933fa2033412123538dd6093ecn/a Quakbot
2023-05-17Jgndssfs.jsjs ac2f114a6bac8df9444849169360217c9656b866153cfc42dc444cbc6b7b6e35Virustotal results 15.25% Quakbot
2023-05-17Qdfle.jsjs 00662b73e2bd3a971290d1314c7c89f0f6d0d7244ebb8fde1721be20fa50a8daVirustotal results 30.51% 
2023-05-17Dvdv.jsjs 64dff88a0434f88beb3fac1ad7fb2945b374f90e6ee2ee7322665681b945e790n/a Quakbot
2023-05-17Izqnaup.jsjs c419bc2833e48f8f26166ef911d3915be8fd0619ac6a0e0638813a4404df6979n/a 
2023-05-17Qrsi.jsjs 4add59e7db2bfbb90082af7375ebe498d79e459da23ede4a9b7526ece534b777n/a Quakbot
2023-05-17Vhbbtxx.jsjs ca85f22e3c1717703a46b75115ecb70f3f38dafcd3ce78b91fac13ed83ba5447n/a 
2023-05-17Vtsqr.jsjs 91c480ba445528bb6b1b273ad6f040c19543e8f430b44d1b0e2d72dcab1eb7c5n/a Quakbot
2023-05-17Ctdc.jsjs f27fa6f3dd5270179262f3ff0f6d1cc0f0e376ab19adb7aea6b1ef95c7ea8575n/a Quakbot
2023-05-17Dfhj.jsjs f261008faf1fac37a3b70851142c76ab9ef018777bf2c8e96717f20367eb8378n/a Quakbot
2023-05-17Oegmj.jsjs 815edd6d5eb7b7ec0f9834b9caf45ddd522a1b2c181d2cf76956f87db76f4be3n/a Quakbot
2023-05-17Voovcsp.jsjs a4e2f44e8ff2a0c6dc1bacee8fb69a882d659e11fd11a1e6bba23b4fae9dae38n/a Quakbot
2023-05-17Uyqffs.jsjs 63f856d92e61e25d62811cb37dbd251a395ad3fd56427abe9184b117773305e0n/a Quakbot
2023-05-16Sjzdkrdw.jsjs 74e41f404ec04437b65a6a3215718344cbe85120f08eaca8788d1d0e048a827bn/a Quakbot
2023-05-16Ijqal.jsjs 22bb7501f616fc2b29026563f3facf79b69662eb7c95adca55f0a8b5d83c115an/a Quakbot
2023-05-16Wsbyxi.jsjs 7919ce43975032f2c32c995b338f4564b25531a6f037c74fd4e5872159417ea7n/a Quakbot
2023-05-16Rcgc.jsjs a48ad0026a0ab684bd2998fa6e4765a110b0b2238d0e666f85eaa37574c00fe9n/a Quakbot
2023-05-16Fjxt.jsjs e832c27bf0f9c65a5b41e084db9eab7144c242d2fc9e8758ce3d996f0e0186c7n/a Quakbot
2023-05-16Xcwyz.jsjs 832ac682493e88359e2fcfdbb37889f99506378ec4fdfd0305564c9245cc4caan/a 
2023-05-16Lxqrmx.jsjs 52dae536ad9a20604d398a309ac753af380f7401575da5d585083e35e1c320d5n/a Quakbot
2023-05-16Zawmt.jsjs 6fb8ceef30d6d260ff47547213ab235c806869307a6a640aede1f2a09df1854dn/a Quakbot