URLhaus Database

You are currently viewing the URLhaus database entry for https://spvcph.com/auqr/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633894
URL: https://spvcph.com/auqr/?1
URL Status:Offline
Host: spvcph.com
Date added:2023-05-16 13:14:23 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116523 created on 2023-05-16 13:15:14 UTC)
Takedown time:2 days, 8 hours, 53 minutes Poor (down since 2023-05-18 22:08:21 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uxaeri.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Rexfmtbx.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Rbkvbtav.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Aplr.jsjs cc45d965ad2af0e4b8c37213e1adfb9d9ace1d6f7f89fc6195e874b709ad03f0n/a 
2023-05-18Cezrlc.jsjs 4df2da0e1a60159c49866a7e3899e305f80766c9bae6b676bf18955d4e2ee8ecVirustotal results 15.52% Quakbot
2023-05-18Hvfyftei.jsjs c977474e11ea0066144f719c48b4f2d5ae32da3a13eab7d64cb3433546b8d738n/a Quakbot
2023-05-18Yfje.jsjs 39ac88782d43b40c56cd7245203211f747e986908f13072c8d6d6caede0ef79eVirustotal results 30.51% 
2023-05-18Qyxiovqx.jsjs e3086e125c0def5547c4247942eaf8cdeb0e4e581562f9cef5e20b6978761c61Virustotal results 32.76% Quakbot
2023-05-18Cgohu.jsjs b96c9289fab9b7759ba3dd4ea2b84064aa296457443d10064d033d225609b55dVirustotal results 23.73% Quakbot
2023-05-18Onuwj.jsjs 5385fad188601d9e6dde0c124799956c0f227ef163e10a45533ba701150ef12fVirustotal results 11.76% Quakbot
2023-05-18Snzj.jsjs 36fa7b7d4e7fc7c9366c2fa6533c47fd96cdc2d9a6f2c3a9025fc4271c5d4c18Virustotal results 24.14% Quakbot
2023-05-18Dqep.jsjs d72be2d3e9fcadaa237d2573ff95eacd51e973b70514465c8d57e7cd957769b2n/a Quakbot
2023-05-18Zxkrcc.jsjs 0b5625e5e6c8ca17119f220fef0e5b08313f77e79294375e8b2c57d9bdc47ca9Virustotal results 25.00% 
2023-05-17Pafiim.jsjs 2dba215a58d9e94365ddf7dad401aaefe0258795b13308a0521c655fc8cbbb26Virustotal results 15.52% Quakbot
2023-05-17Hxti.jsjs ff50e9d6bada1c148165cd94d8242cd7c0651692a508bbec763046c0ad17be90Virustotal results 32.20% Quakbot
2023-05-17Igqdnpr.jsjs f3f5b182d275d4c04caa73e7abc7c40748f810123832c294c35b3b4bf997ea3eVirustotal results 27.12% 
2023-05-17Nmzm.jsjs 714d6297effa9020249e19940853d50dcb2ba31d5301a716f34ddf73f9a58bf1Virustotal results 28.81% Quakbot
2023-05-17Hyiwe.jsjs 3b413252866f0b4261ccf3b4972d86690f29353242c85733133be84940ad6fa3n/a 
2023-05-17Qbgrwwr.jsjs c321a1664d74da4f73b983c793c4059b38202d4116be2e9f53f9aa1d4320d830Virustotal results 24.14% Quakbot
2023-05-17Daqdlcug.jsjs c5b4c29787160ccb71f79ff6637aeac99008ef606c71a4b14629e1281f03f74an/a 
2023-05-17Upcy.jsjs bd4c582c89e9f55a53ba531ff28d8f9676765b3c5fbc0bc80e150d66af8516fbn/a Quakbot
2023-05-17Bfqes.jsjs f84f2d7cdee9377689f20aa651e6598a5fca11cee1a46e671c327d793db5b502n/a Quakbot
2023-05-17Klbbwf.jsjs f3a70b7e3aebce38f9be5eca5347f24a47e0393ca7a368bde822768c27db9297n/a Quakbot
2023-05-17Etfveg.jsjs bad995ef69e310d969d16c64bb7406596d6c348cb59ac44cfec588196defe61bn/a Quakbot
2023-05-17Kgutcnx.jsjs 088dea640e435ed560d465e50709f1d8c887f55b2802587c6bcceafecd974f98n/a Quakbot
2023-05-17Lkmybmu.jsjs ffd6326d181de4708bb3cf0c99330833ca220b49284696afdeb61d38d4d8d3ccn/a Quakbot
2023-05-16Osxhb.jsjs 94f5cbc4a7b7e8e429620d91d79c248a761f3da59422c188ba551e3130ce243en/a Quakbot
2023-05-16Fscuohng.jsjs f32574396b64d170fd13e547f5d66fe09408512c6343b883f0e1ae4eb5ecaee2n/a Quakbot
2023-05-16Qbuk.jsjs 0adf506dd51feca79628c63f461ef57b4be43e66ff5c5d8f962da9039d86ea63n/a Quakbot
2023-05-16Vewmk.jsjs d8fd07f188642751f1a4421a50fdf14427319b6d1455994384966d35a6ab7606n/a Quakbot
2023-05-16Bqqn.jsjs 4947a58e8a4af8ac4b1d969f72485238e38acae29af71cde4e989fb1e1dab435n/a Quakbot
2023-05-16Sdvldxu.jsjs 35c4abec214f06ca8e0b4847b482b204f6e5b347d0d9c3a85f1278386e1691c1n/a Quakbot
2023-05-16Fwcfircn.jsjs 49aa1f0124328bcd6ad3db5a5a484d0c94efcea216cee3ea0aebf7ed473dd27cn/a 
2023-05-16Bfbmzi.jsjs d547cd9826b831b940eeedbb8a8bdfec38e62aa541e0668aab8fedc856c28f1bn/a Quakbot