URLhaus Database

You are currently viewing the URLhaus database entry for https://examexplorers.com/uspm/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633877
URL: https://examexplorers.com/uspm/?1
URL Status:Offline
Host: examexplorers.com
Date added:2023-05-16 13:14:15 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116518 created on 2023-05-16 13:15:07 UTC)
Takedown time:2 days, 9 hours, 34 minutes Poor (down since 2023-05-18 22:49:16 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Rktvxdx.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Qytn.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Pmds.jsjs 18bc04176f89d93558a971e97e70d64742625640ef84e7f7bc8274a4f8f7b6dfn/a 
2023-05-18Mhcm.jsjs 5284d5807da5986ffb17fdd9761066974cb34030eb5067e7f9a65e48b32f37e8n/a GuLoader
2023-05-18Ufhlcy.jsjs 7f1024ee7a57ad586eb6a36dbb25ba4f7e78cbd55b3c87d5209716b7628bc53cVirustotal results 28.81% Quakbot
2023-05-18Pxrou.jsjs ff50e9d6bada1c148165cd94d8242cd7c0651692a508bbec763046c0ad17be90Virustotal results 32.20% Quakbot
2023-05-18Otzvd.jsjs 07cd66f1c775da49daf409f335ec5d0189ba991d2e66c33b01708efe1934e0dfVirustotal results 27.12% Quakbot
2023-05-18Faov.jsjs ecb53b7bd1821908e3358a50f35b5cc1aa92c43f7c190eaa7e0e473ca199dfa6n/a Quakbot
2023-05-18Nybmogog.jsjs e98ab08e4897807987344800297aa41a72fc207a57b0e89510243b3b8ad0e144n/a Quakbot
2023-05-18Tbapz.jsjs b8080e6708e687876e70fb9577bdb538b92f84133aae0cd311c456094c77efb9Virustotal results 25.86% Quakbot
2023-05-18Jktpb.jsjs 33e5253fc3841fb30d4467ba7144f20b94bfb5714befb85aa32837899b33859bVirustotal results 27.12% Quakbot
2023-05-18Qvmlzs.jsjs 0c72f8db70d3f144ec7cb21515e337377b9aa689dad88dfbf1720634c8b70453Virustotal results 30.51% Quakbot
2023-05-17Fbzavohi.jsjs b267e2261f79527d447d6a639751fcabcf68f9640e62a3c3106b4f750cb07b66Virustotal results 32.76% Quakbot
2023-05-17Oyufyvi.jsjs 45a695a6696ee2284f34ef03f76d7192a3829a64f1ae5f5216bfd36983231680n/a Quakbot
2023-05-17Iytvmhm.jsjs abae955795961dc369ba3d41196f2f4238001efcff8a2dc429ababf4821ca7f5Virustotal results 22.41%
2023-05-17Blcbh.jsjs c2b560cbbb7dc30cad06a2a6b715f07591269b172bde5101a639fbb04e4dd9cfVirustotal results 27.12% 
2023-05-17Qsouraz.jsjs d6cb8ae70d4f102ac987c9de47abc6d962e10fa9755d74ea54a68edb6173dad1n/a Quakbot
2023-05-17Niux.jsjs a5ad0d19dd6ae50f16dc5be1921c43a887aba5ab8dae04acbea417a5cd62d61cn/a Quakbot
2023-05-17Mmpu.jsjs 3b02a052d8a0b81df8e86e1d6615bbb499f28a8dcdca9fa90aaad837b840761en/a Quakbot
2023-05-17Byijks.jsjs 25a8177ec63729e3f86c1df0b869ae741042ef00c9b11fdc6d160e3d2983c410n/a Quakbot
2023-05-17Urtkwqz.jsjs 324c81b22e388a10c90d8fae1b9709dde1747c7ee1d6747b505355fd973dde88n/a Quakbot
2023-05-17Lzdzvzow.jsjs 1d5036e0dbbdf3256bb1fee5c93a80a3a0fe4089b83826857c96b1a2848ae316n/a Quakbot
2023-05-17Pkpaq.jsjs 3a04ed93542332b6dab28ef6fba724d8ea6ee3a0131e6c047f61bdd16e1399b7n/a Quakbot
2023-05-17Ccqdpcfe.jsjs c6c9c0e5605b5acca8c19ac46b835a8a97bb47d8f73a90aa3eaf9476b62c0d64n/a Quakbot
2023-05-17Rwbhyf.jsjs f992c3a49226305d4efbc2c1e1b2a454cedc0312dbf32a5422d49e3872eda7ben/a Quakbot
2023-05-16Dikjuux.jsjs 094644fbec42c7127273dbcf43f95327123928d881b44915f61be40457c27a7an/a 
2023-05-16Ejxe.jsjs 48e38988c3d108ed3848a2a98d641074573d0562eee0f67d3d2207cbfa0ea47en/a 
2023-05-16Hclqmw.jsjs 40ac0f738c8b429efb3c3dae7b604b71b850956c44a6800d19eab6c79bae015cn/a Quakbot
2023-05-16Rqvt.jsjs 6fb1e87b615d45e1ce1305efdc728c72ff6177422978633ff05c0d91ef004528n/a Quakbot
2023-05-16Pdghgjqr.jsjs b073d6e8f77a0ed5b98db7b6a6f3af9619bf69df8ecda0b4bf2f69cf8bad2bd0n/a Quakbot
2023-05-16Rfax.jsjs da594d37b71490069105e6d1a6137f39024cccb48e9aaa79161db9a8153689fbn/a Quakbot
2023-05-16Ogya.jsjs 0ac32ed006bf3380f38ce6ae1d440ea902de846093c49d16b104fbad7315a105n/a Quakbot
2023-05-16Wqwypsb.jsjs 12680e27eeb0f152fc5b965d34a495ef3c4e66a8da9711d9606cf513185f2cden/a Quakbot