URLhaus Database

You are currently viewing the URLhaus database entry for https://1coner.com/lual/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633886
URL: https://1coner.com/lual/?1
URL Status:Offline
Host: 1coner.com
Date added:2023-05-16 13:14:21 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:15:56 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 7 hours, 56 minutes Poor (down since 2023-05-18 21:12:51 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Iprzbphe.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Pinv.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Icbcvhw.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Fgslgq.jsjs 3fb6bbc76e84a11a15770ddbead7e5078714534021e93c398aa1415f761a8aa3n/a 
2023-05-18Maba.jsjs 66a44d6ecc0bff8550c4f8fd93b40851e019bac6297339dd180d268ed9bba451n/a 
2023-05-18Pdrc.jsjs 5385fad188601d9e6dde0c124799956c0f227ef163e10a45533ba701150ef12fVirustotal results 18.64% Quakbot
2023-05-18Zkgntf.jsjs 4cfd3cea6e5aacf340993648b46bbd6628953021cc5148be665b68de39755e98Virustotal results 27.12% 
2023-05-18Lerm.jsjs 4a2d1d02742e1dbb3fdee1d9ff6862a5a45e7920404df24a06740007d4b653d5Virustotal results 25.86% Quakbot
2023-05-18Idnix.jsjs a99deed91507b2e0aa98b17753892aa733b12eed707f493c38359420a3a4f109Virustotal results 25.42% Quakbot
2023-05-18Djaoe.jsjs 04b3f1f116a7708cdedfe0d8666eb67090ed3a68f9536288919107e395a0fef9Virustotal results 27.12% Quakbot
2023-05-18Gjvp.jsjs 9dc74a47b57fcd85200f975b411792401c29e5d1ac2806f4efca47c4fbc00eben/a Quakbot
2023-05-18Olqqhjke.jsjs cca9ae0f45d9d362a7e18d9f86ed7a18a1340c3f3d4811c7a2ddc658408bd496n/a 
2023-05-17Hnhsnrm.jsjs 644d7490c3fe27e34ffb24eec109bfe9aaaab1a088b489de784de77611e65df8n/a Quakbot
2023-05-17Xfnd.jsjs c7f9d6c56a28ecc44744a1c617778af39179d5869bca0ccd518016eae401078en/a Quakbot
2023-05-17Qbaqmh.jsjs 09d00cc1758af4e79c7a38e65ba9555ccb18dcc1f628a22c1d9bd5a337b03d88n/a Quakbot
2023-05-17Pixhpc.jsjs ba0c34e538207bb899f624292efada218b4202e276606cdaed6e258bd29572b4Virustotal results 25.42% Quakbot
2023-05-17Cuipk.jsjs 55ba4dfbf0eeacaace5287a51196c8d2e3c7ae79a65fd07a27fd6024ca40bc13Virustotal results 16.95% Quakbot
2023-05-17Afqmkh.jsjs 3bb4e5803055d8c3ad6250df56ce21b663c3da855bc32daa9ecf204060498681n/a Quakbot
2023-05-17Qcsrrlj.jsjs 743cf712f367f3c69cc6bfc3a3734a66d19bef6e76aabcc6a8b97c534a3b5557n/a Quakbot
2023-05-17Gfhprbud.jsjs 31bf7d681d20e34572e4430661d21d41673bc01c1da5ef7087eb9d8836ba42fdn/a Quakbot
2023-05-17Ktnzv.jsjs 9cc1641b60d649fe91b99a1a9333fb48497fd104c1c997a4ddf573606b60f7c8n/a Quakbot
2023-05-17Ncxf.jsjs 5b6c6c89b3031d947eb8420a46800784eb3d659a9950929dc6e93e4065e37d7dn/a 
2023-05-17Udkk.jsjs a2db74b02e6a04fba7a7d74e252b194f261d1dad688195a21255a8077e761069n/a 
2023-05-17Leueva.jsjs b550d56df2b8162661f8c50b3bff48d3a86a54c076b5513105caa6905d98e0e2n/a Quakbot
2023-05-17Polsejeb.jsjs 021dbb6ee5ef5cd5b3e58809fa5c9800938d12b695162163df74f9fc8e37be05n/a Quakbot
2023-05-17Nfowq.jsjs 898141bb319731db91a18b229be5fff53ee578b607853c54580ae26f75c1b67an/a Quakbot
2023-05-16Baocya.jsjs 198488f26d8ccc549c2598aa022df4caa736e03aa8bb6a4ddc44cbf548bd8a88n/a Quakbot
2023-05-16Lvehvogq.jsjs 015754b515fa735847c5966f8df502ba504c8b00461594ce0c80567aab1b7e34n/a 
2023-05-16Iovyk.jsjs 3f2dbd1253ced970557cf63c23aefeb5328869af52137fb7c17ab608c602dc94n/a Quakbot
2023-05-16Zbolkmlm.jsjs 4f3e40ec03dc64f22d18b33b911d3d503dd4997e22cf518fc02b53a7040af3den/a 
2023-05-16Eexcvk.jsjs dc956a09dd0e3a3fcdd8da1c770283a01cceb9f633c07206513115878cbbfdb6n/a Quakbot
2023-05-16Uoihsmtg.jsjs 9be0ba8bc4740d7b4e1eb3841c79a44d7e8fbcbb314e0fcd6bd6b39906ba9cafn/a 
2023-05-16Selqeoo.jsjs 8104fc4d0b3ddcdc47e63da7caaa9aa10fca73a00f025d1c86553bcd3dd8fd1fn/a Quakbot
2023-05-16Iucdg.jsjs 9b6104906b7dbff52ac3bdb9896acbb29081fec10674e84837c1bd9eb0c3abf2n/a