URLhaus Database

You are currently viewing the URLhaus database entry for https://kakapastipuas.com/toaq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633733
URL: https://kakapastipuas.com/toaq/?1
URL Status:Offline
Host: kakapastipuas.com
Date added:2023-05-16 11:26:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:29:11 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 9 hours, 31 minutes Poor (down since 2023-05-18 21:00:19 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Pnrewqtg.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Exmr.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Zspdomv.jsjs 059a81dac32434c96bdda5e1f9a9575c7daea2883c45e47e6f1a84407817c35fn/a 
2023-05-18Pxqdxpp.jsjs f3cf1988e5b288b64fc34cf15045d67a4fcd2c9c61549510e3df907ea1f61cf8Virustotal results 27.12% Quakbot
2023-05-18Vqhvfgs.jsjs 5ed8c2a8ffd44a6f80d52c65210bcb3ab9bbfc42a217a03db9d435fe66f68833Virustotal results 25.42% Quakbot
2023-05-18Fipmy.jsjs 5c57b539392768e2e9e8490f11f6528d81875b4aae44e11319d0a94af50b1f00n/a Quakbot
2023-05-18Voxtdfrg.jsjs f276da1a81b23b7f647bba9fedb53f4e8df35e0456b09c909184c6c45bcd9d99n/a Quakbot
2023-05-18Giotmkgj.jsjs e5f9fc33236b5ba2988d71e8585b3802d96cde07263ae499ce6ac56cc9db183aVirustotal results 27.12% Quakbot
2023-05-18Lqqgyz.jsjs 345e76a5091b5ecf319a57a8901fc203f48dae4dcc62b70fdc4d1e542d1a1f46Virustotal results 30.51% Quakbot
2023-05-18Hnyczaxh.jsjs 8f5bae7c3310650dc125b9223695f4a40a6d1394f6f6f9dff466a3e53099ba7en/a Quakbot
2023-05-18Lbshi.jsjs e6823880248255f28dad73af6553cfbae133b6df9f78eff124a379d793265ac2Virustotal results 27.12% Quakbot
2023-05-18Qtya.jsjs 55ba4dfbf0eeacaace5287a51196c8d2e3c7ae79a65fd07a27fd6024ca40bc13Virustotal results 16.95% Quakbot
2023-05-17Oilf.jsjs 882f433be14420954cf276d10abb6b832e89ab1dc301d2d047538fab217afdabn/a Quakbot
2023-05-17Sdcfn.jsjs c97e0d75191c3cd583de9edf9cef56be0b4b4bb3e072a64e3fd6133eef6ea96dVirustotal results 25.86% Quakbot
2023-05-17Gartkey.jsjs 99ad6e2718d4fa53c8b3e7479802548afcde5a374d0563ab49ffb0405d8e435an/a Quakbot
2023-05-17Kqdevx.jsjs a2fee1f921c59d61590ed86bdd9e19a12b68d9722d228d0e5bef678bd31d461bVirustotal results 30.36% Quakbot
2023-05-17Fceem.jsjs e8f221308008303d546d565fcb2601b794a95ce83d609f81b4629c5284a8547aVirustotal results 24.14% Quakbot
2023-05-17Bxfwrqa.jsjs 0ae16f66866567a01f4af47c0c7b2e49d1e54eba4e457b2de97f88c48016cedcn/a Quakbot
2023-05-17Kpnmhcnv.jsjs 8cc89db867d9380f7dc7b54f586907e61c8f17e7a446d25f889b80f0d6f9bb9an/a Quakbot
2023-05-17Rqmpy.jsjs 450f3accd2f2aff67d0c711bc7a401d448408c53cb6f26b9e70a477353cac4c9n/a Quakbot
2023-05-17Zztbfnz.jsjs 7424f75bac4475e7c8eed296357a875bd95833c04e56e7121ed7d1b3bbf10488n/a Quakbot
2023-05-17Kqcja.jsjs d044a31ac6ca82d54456d5cc05ba7fccbc01fba290754d2086ffd25095202b1en/a Quakbot
2023-05-17Fqhxsa.jsjs 84311842896212167bdbfe843794c480dbbd983676c84d786ff92e250b949bedn/a Quakbot
2023-05-17Vruxdqis.jsjs 2c23f286028ad984ec0693a168227276c759e25884f1c284e36de588fc1f247cn/a 
2023-05-17Jaobthnz.jsjs bb90d03bb559f7639b2ff927faba58f12a0a27af8f64d05393f3e441cbe647e6n/a Quakbot
2023-05-17Ojgku.jsjs 98921a400278c9a9488f4d1aac0c5d851c052fec56eb91eaaad4cf1f001880d5n/a 
2023-05-16Uqctzdvy.jsjs 8937a07ae54ee300db57de157a1c0474e950a92169bea33d6c7030e31f57c0c1n/a Quakbot
2023-05-16Jxgibkim.jsjs 624ae78e0c3c895e06d5259188d1b9923672798259a8a4962c019940b467468cn/a 
2023-05-16Rkasg.jsjs 1a34022bbf5c07500aa9c095116bffa5a82675688a454947fdf536feaa459437n/a 
2023-05-16Kzdi.jsjs 0973a928daaad6c2d32d9a2b13b08fee3f6502cd65bbb37c446af7f0d84a6dfen/a Quakbot
2023-05-16Rptcduhz.jsjs 6e216f3e090bb6ddaa1e5d9fc528afb00602298ba274964461b4d1365810eb75n/a Quakbot
2023-05-16Tkerwjaq.jsjs fb1f5ae5f6430a43189d5f8104a6471c6d2256e55008693e2b81afed190985a4n/a 
2023-05-16Jbcuvf.jsjs 411ebe12c6b2a1fb4c9e827a0ddcc971cce41a7af153f1d886579140d7a67994n/a Quakbot
2023-05-16Qqwmpwe.jsjs ae121bcf0b1bb3bf8a611cf854957b218041d9a8c2931fee069c1c93f9fb8bb1n/a Quakbot