URLhaus Database

You are currently viewing the URLhaus database entry for https://rootalacati.com/tsi/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633743
URL: https://rootalacati.com/tsi/?1
URL Status:Offline
Host: rootalacati.com
Date added:2023-05-16 11:26:11 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:29:22 UTC to abuse{at}radore[dot]com)
Takedown time:2 days, 9 hours, 37 minutes Poor (down since 2023-05-18 21:06:39 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Wxvqajq.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Flojyglv.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Nyctoi.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Zqdiw.jsjs 30178c87c53066fb3b0f0dfad7264480e7f3acc9adbcdfd1d00ed34e90926fb3n/a 
2023-05-18Zxxdhsj.jsjs f1cd10870a25ff5450774a8498966cb5bddf350a269b79fee66a198f6cf3b7a6n/a Quakbot
2023-05-18Ohbkdjyn.jsjs 90d7044e2b3c6695b8ce4be887d9fedf198e2631c47d77093e427bbdc2ff19fdVirustotal results 29.82% Quakbot
2023-05-18Ptidafl.jsjs 6bf7410f1b32c7fad44030961607fb13ec400a2a008f5817485ba84c5c297175Virustotal results 27.12% Quakbot
2023-05-18Usvg.jsjs 47831ca3235332c96696b1add7425b7dcb044b9de06934992957a5e00cb4dadcVirustotal results 25.42% Quakbot
2023-05-18Cxech.jsjs a45416e3d9aa47760feeee7375be42c3748b04b0d9c6c573bf4db2cfa07929b5n/a 
2023-05-18Cimb.jsjs 3938ff8a3f26ca0c121f461afcbf7394844e31d1fb9e68757fd98de2a4b3238bVirustotal results 23.08% 
2023-05-18Ybvzyzxp.jsjs 2072042cbdf8458366261756217da566a1b8d6cf4b24541a37d71c44c07c7fdeVirustotal results 24.14% Quakbot
2023-05-18Qignnr.jsjs 7a515185d1c204dc897de0e485dd2dd335341156b5b7764220fb6df27fdbeb16Virustotal results 25.86% Quakbot
2023-05-18Ppvf.jsjs efc10c85b0f60f774980c7250e0358ab61ded2a4d2f8fed854bf14d05af6908eVirustotal results 6.90% Quakbot
2023-05-17Pksr.jsjs 29d88d7a73d988b2b2c5ddc76ac150742366a2a8c379758bf47f13c2fcf01346Virustotal results 27.12% Quakbot
2023-05-17Bmmedtj.jsjs 4a5bb0d1af42aabd643a23c518cbc77c4a2931fab8d180bbad1c0ea815f5954an/a Quakbot
2023-05-17Woyatch.jsjs d112f357338680817dc9cfe7ce64d7ab03de74008f16c43f1ef94b38bd159af8n/a Quakbot
2023-05-17Zwnac.jsjs 3cc62e68f657fa870eabb640cd8e651d4ee69a242db9feadeecdbe6a0435ea99n/a Quakbot
2023-05-17Xxjwhh.jsjs ed3b42a466d5debc63224e8439d69996fd4f174cfcae800ac31dd8dcb69c921dn/a Quakbot
2023-05-17Xddyuhx.jsjs 0c7ba195ded6d8e316021ca662000aef82b48c95dffdd60c2ea37f1849c555b6n/a Quakbot
2023-05-17Dqflug.jsjs b8f021f9cc5423169bc8a78210220d45ae701382d43568f3cfbf05a6adc88f23n/a Quakbot
2023-05-17Cuhmbjg.jsjs a2614fc00f8445d0f28a88dbd9b0c74be9a085cc85fe344de15e4e2dbf5eebb5n/a 
2023-05-17Oghl.jsjs cc78272637bf87773cf817020a2f409e1d7f6ee6a9aa6c2e9276b4b0782da4ebn/a Quakbot
2023-05-17Ihzh.jsjs ac9fce4dceed42d446c1f7f59f688f829ce346c304338323b7a2ac5ce655d884n/a 
2023-05-17Hncv.jsjs d25a65dfe68c8d1b6beeb5e449d5e7025051b95bbb33e184a95acfd88adb84den/a Quakbot
2023-05-17Kqftp.jsjs e922d192231b6992b978c8c4deda9b8a6db70898ba2bfee96b6c4d91c87202ccn/a Quakbot
2023-05-17Udgfav.jsjs 052e455930fbda7e813ec5d15b7f2e0e40297549e83babacc95d0fcc5ec80368n/a Quakbot
2023-05-16Dhid.jsjs 41c0e47ab702aede56e2fdf6884e111d8be95a53eefd35c9b6f26f23ad55a827n/a Quakbot
2023-05-16Thmwyeb.jsjs 436dd55831dcc6951194155bdfafdc5984cbe212684a5a2cdee39a3cf9fcce0cn/a Quakbot
2023-05-16Rrmz.jsjs 003f09b7602a4d5d6c6085a00970b48001cb0b3e2b604f5d765dd0de29f9ef28n/a Quakbot
2023-05-16Easx.jsjs 97ee95bbedd1242075cb5da5f43ee759a9dc370755225bb0ef164c517e42dc16n/a Quakbot
2023-05-16Fqiea.jsjs 17662114d2b3e65cdfa75ffb6da75a72f91ce726873e218b3f9574ce333529een/a Quakbot
2023-05-16Oazffm.jsjs 6c7c66c7f2c16605a25f953af2e4af05cfcac02a226dfada349acd64f6a86cbfn/a 
2023-05-16Gjekcgpz.jsjs 0a7a6dcdeae4217d6e91bb7de82600660532f76073fa34e3053498e431177d04n/a Quakbot
2023-05-16Dgpo.jsjs 453a59ba7c4710c53f645b120279204f574517a9dfdc7f02d2d4ea5b69c116b8n/a Quakbot
2023-05-16Ilcj.jsjs 681f1c12193042d1001cca8eff9d64673d135dc93613ed9356802b0e5e6ece19n/a Quakbot