URLhaus Database

You are currently viewing the URLhaus database entry for https://essayever.com/iif/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633906
URL: https://essayever.com/iif/?1
URL Status:Offline
Host: essayever.com
Date added:2023-05-16 13:14:25 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:16:15 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 8 hours, 22 minutes Poor (down since 2023-05-18 21:39:09 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Dygjupwq.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Takuvxqw.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Nnbtbj.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Snurd.jsjs 43cbc94bca27c15a01d6efc3da53ebd02dee68120fc7856697be2864ad6cd8b9n/a 
2023-05-18Jnmglh.jsjs a5f0035e2f6ab21d643775a304ea994d963bc0ad712a5ae1a9ebb1a5298f7adbn/a 
2023-05-18Xlcjnfns.jsjs e50fb972f8f78042286895b6d869daf014f5e8082e3c3989ca853daee780a6aan/a Quakbot
2023-05-18Hcmfiys.jsjs bb118ed7175733d7b31163818a3948e5e35d0e3ab3627a549e93cf6afa196585Virustotal results 29.31% 
2023-05-18Edrw.jsjs d188bb106c47296a6f358dc69226ce3c9b48abe1399e7cf924fc4afa813b1505Virustotal results 30.00% 
2023-05-18Akgxzvtd.jsjs 9fc93269f064d50db15333e3dbcf15dccb35094dc51bedfc465ba99ce6a37953n/a Quakbot
2023-05-18Ltkuint.jsjs 03cdab834b6a7165627af8e82df4d52dde740aa3481625a88ef76e122b7b2894n/a Quakbot
2023-05-18Kkps.jsjs 3833419abb83fe2369255a23b3fa983e65047ca005c0dee0d772efbdbf8ee75fn/a Quakbot
2023-05-18Uxoo.jsjs 9ed630b44354fa9a5b12648e092b487dbecee08d6aad53bf5d2695dbea9b9cc6Virustotal results 32.20% Quakbot
2023-05-18Qkesi.jsjs 5ed6c54055399ee6ffdf3adfc06337fb1dfa9ee1a6c1766091b74c1ebe2ebda1Virustotal results 27.59% Quakbot
2023-05-17Fblmiz.jsjs 148425d44762a381cbc5cf7c9e0e7fb44d71f7162439e78b219929274f34d19fVirustotal results 25.86% Quakbot
2023-05-17Iybfur.jsjs 99ad6e2718d4fa53c8b3e7479802548afcde5a374d0563ab49ffb0405d8e435an/a Quakbot
2023-05-17Sastbo.jsjs e78861a712a577b61558f7ea9878b91e974692081e5daa5f02dcb5ff1cdc359aVirustotal results 32.20% Quakbot
2023-05-17Mtlnlmc.jsjs 3e31ea9bfd38c94deda13767d5f82b55906ac8a767e595d59f2fbc92588d23e3Virustotal results 32.76% Quakbot
2023-05-17Dyogqmp.jsjs 16fe8055701bf9e829e70c4811b31fc75aec4d03582697ab493fd530e84ac6cdn/a Quakbot
2023-05-17Tqcauz.jsjs 27d3fa3ffa307f97bc3047f15898d338734929484e224f43ab8740c710601a78n/a Quakbot
2023-05-17Ihxqxg.jsjs 983c9fb0828b90c43eda528aaf767c2c7d4b71d59b86ad0d04461db11d91794bn/a 
2023-05-17Jnzydsne.jsjs 0c7c96dd589f0bc1676f7af1371bc70cbf50d310293d070ff8e1fef3df4533f9n/a 
2023-05-17Vlpzygkq.jsjs 44d22617d2908c048934b3273a60f4791a550c9aa04391ac52613fb2dc759b91n/a Quakbot
2023-05-17Cjpok.jsjs 71d33e093c2aaf1b4135b987352e6ee2f0e571d3e3787d1dec87bc9d73e485b6n/a Quakbot
2023-05-17Ezqwu.jsjs 4460acd7a318438e8d9a7d76e6ad2aefcb55a03ec665fa701af63eedb7c0239dn/a Quakbot
2023-05-17Yydpfie.jsjs f20f91144636359ad2672b69fe2dc0c0b876e353a610bbec36f8ff8f22d04cf7n/a Quakbot
2023-05-17Cois.jsjs 967dc4d467c20ab2994eb0089a79315fb190b38801dd9cfb4bf34cfca4c0c794n/a Quakbot
2023-05-16Jmyttdb.jsjs cc83aae1434cd693d10abc2652e936fa3c3edd3a4a25989927826f2484ff65a9n/a Quakbot
2023-05-16Myuvwu.jsjs 81b9c470cf1ced5001b21a29ee515d7eeaf96d772d64ea6040dfa12c311525adn/a 
2023-05-16Iolaus.jsjs 6282c92cb1b17b9b17e4b58cd3e53d8894956a75450c83b421c29b4b3b643359n/a Quakbot
2023-05-16Qmooroz.jsjs 6166488030513c5dac57da0e6a1a39002422f5af1539e43e8608bcb986aa39c1n/a Quakbot
2023-05-16Ixet.jsjs 561ccae8bc93d3f271916ec5b8924e2db5ddc1df0401326c5a34d291f3197bfdn/a Quakbot
2023-05-16Fllwqr.jsjs c8a8c47c969dfb8b5e0b6798d51d13951f79ebdc1d46b5b9f4d0aef477e4c24fn/a Quakbot
2023-05-16Xoiigrgn.jsjs eeea6ebf5af8878bfd75329365cb58a86db56eba97741e8ec1bc21a4e5e24f50n/a Quakbot
2023-05-16Vkls.jsjs d3fd8ba99fe5ebce9d5976110a17ffd654218993a8366ffe943edf8aff7ab189n/a