URLhaus Database

You are currently viewing the URLhaus database entry for https://thefalconandthearrow.com/tp/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633895
URL: https://thefalconandthearrow.com/tp/?1
URL Status:Offline
Host: thefalconandthearrow.com
Date added:2023-05-16 13:14:23 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:16:02 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:2 days, 9 hours, 27 minutes Poor (down since 2023-05-18 22:43:20 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xaznyxo.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Aproldxx.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Bxxkcmql.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Tsfpl.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8n/a 
2023-05-18Hfgj.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182en/a 
2023-05-18Ctoyaaaj.jsjs 8496ebcccb2676a1fb21ed0fdf36c320fabcf9036d275af7acc025b0182e7963n/a Quakbot
2023-05-18Cscwqis.jsjs de678b4a37c6c15a808f0289a0185302b696546ff234a9c180ca99ac8bb1f313n/a GuLoader
2023-05-18Yqsvmsw.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-18Ufeqnk.jsjs 1a3fc3e2d336f6c024b0a452cf6eab7b5521bd6591f7ff15ac80caf4af268c3aVirustotal results 32.20% Quakbot
2023-05-18Adil.jsjs f276da1a81b23b7f647bba9fedb53f4e8df35e0456b09c909184c6c45bcd9d99n/a Quakbot
2023-05-18Tlhffgfv.jsjs 0eb9fa07ffbdae465ca7afa7b68b6b38311315046844cd6ac97c9e3b77d5fe99n/a Quakbot
2023-05-18Juxkom.jsjs c6acb46e483e7792474a50acd3a7ad70626f538da57050c7153b3061376b4f02n/a Quakbot
2023-05-18Kqdela.jsjs 0d19b7d7e092df5355727bab9cbf454b5b17f90d5380ef6240d0cada7cb5a1c0Virustotal results 15.25% Quakbot
2023-05-17Oelwthkn.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-17Veyfm.jsjs 8f330d0bd33cae1207a38406d6db47ef79a72bd8d18681a4a0f3a3a33ec3e4f3n/a 
2023-05-17Hbemwjpa.jsjs 9f9b7a0d9944437dbf0052fad1d08898979bd6c9a9d937a98cea3c757a5f15d0Virustotal results 27.59% 
2023-05-17Jaij.jsjs c6a62ee43c36edd934b0aecf8cca18487dbc8612228decd3f37357b043e4e85dVirustotal results 24.14% Quakbot
2023-05-17Fpyooef.jsjs 9d55c860ce682edea5933b6e9e441703b00b9880087fafd62ecedabf0665836dn/a Quakbot
2023-05-17Ytotoxhy.jsjs 6b01b5522683c655f6e33fc4ecfa2ef55bae886a543ba306b61dd976a892fe96n/a 
2023-05-17Zjjcx.jsjs 1e70a9e66f17ff9e6e52e2d5d3cb45d2387a5a8ac2644d01e100997ad0991fd9n/a 
2023-05-17Vyfkzy.jsjs 2d427c6436bc406af6a1dcc09809eb06e43ec77b4fef9fd019670984fa28f6a3n/a 
2023-05-17Yebi.jsjs 0ced238afba6c3230965ebf45b3109133f48a363cff80b8a64050aa591fdd2b8n/a 
2023-05-17Kpgrfvt.jsjs a3e65fd97c6dde9936bcd38a57e6054ca5b49948f7c9f0023f5accde8946f031n/a Quakbot
2023-05-17Dtzusvgi.jsjs d49d6b991cc66a7755874c9752ec249af3f34e5ce48a6d2bfe2c48a807ac3cf9n/a Quakbot
2023-05-17Csrogul.jsjs c29b01b95cc04a0ef4d4cfe0c9be125f16d618b495f9a95cb907f415f310eee6n/a Quakbot
2023-05-17Juobfa.jsjs 4587c9d8117cafc4b8b4598cefa8a4ee1c102f15bc702402e24e94af4eeadb64n/a 
2023-05-16Dxoxv.jsjs da9a3e8f8753d851a5d70230cdd2fe0d875caa4b67a77fe367543e46e82bd938n/a Quakbot
2023-05-16Xrll.jsjs 3bcb4d099f9835846daf5cfe964d3244211ca5229d8b2b422f3c992cd397ce58n/a Quakbot
2023-05-16Dzjhxk.jsjs 5a48508990c153d74619e4db531d51568e6b0173851d91977e8124c2fa0711c3n/a 
2023-05-16Xmyqhw.jsjs f4ccd250461201989d585775a3f718eb35078c3f4dbc322a868b4b94ec303ac0n/a Quakbot
2023-05-16Ikma.jsjs 0066019a4015cff313cd9763c57917ad694ca26b8d3458b86766182859418cc6n/a Quakbot
2023-05-16Ifyq.jsjs 7c6895df9a359a387049d81627c6334792667558be863ba006a702ea2922a8b0n/a Quakbot
2023-05-16Wpur.jsjs ddbee33e44e9f3bf0db701c86576e0d7397648743f7887700b5d8be485218b12n/a 
2023-05-16Acydvor.jsjs 92169a6689a32a56f4df595388bb8c2cc88263b36ad6dcc13c00296e12ab25c5n/a Quakbot