URLhaus Database

You are currently viewing the URLhaus database entry for https://pceaero.com/alu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633913
URL: https://pceaero.com/alu/?1
URL Status:Offline
Host: pceaero.com
Date added:2023-05-16 13:14:27 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116524 created on 2023-05-16 13:15:16 UTC)
Takedown time:2 days, 8 hours, 2 minutes Poor (down since 2023-05-18 21:18:07 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xqofdqqj.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Mzhiuiq.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Zwepse.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Sstfp.jsjs 4d1158c3235b93800cae72c8a9641aa378e695736aeb525ead0546bfb2b51b27n/a 
2023-05-18Chhlfzt.jsjs dc0d873178c61dae13dac14d65611d4716e9c28ebfa216e32126dbdd1ac971beVirustotal results 28.81% Quakbot
2023-05-18Rjmyvrp.jsjs 42046702c8332860c6d6224d63344bbd919246deac12c67a32bee542c7cde41cVirustotal results 25.86% Quakbot
2023-05-18Kvvglsr.jsjs 3f2b1d4fe71004830b3afc87d735391d7ff0033d3264baf0b9b84903c52c16f4Virustotal results 30.51% 
2023-05-18Wiesyl.jsjs fd6447c1e9b59d7114534e32bd988bd00fb674bcecc4c3d958b096bfc06b4acaVirustotal results 29.31% Quakbot
2023-05-18Jbwqhz.jsjs 582d7260d0c9d28291c1a5741818450399bdb826da9dfa44e69657727548f4f6Virustotal results 25.42% 
2023-05-18Cfigee.jsjs 939b394768f864f5af2b1e196cb9982563bcbf1157f23f9a873030ba262566c3n/a Quakbot
2023-05-18Uzamcbl.jsjs 9695d2ed6261eeebd78cdc70e45105cb68ff36705197941a93e942a4f861ab3eVirustotal results 25.42% Quakbot
2023-05-18Lsemughq.jsjs 9d4e35c32d73270df3c5bf64cd693e2933e614075af8f15eeacb3fcd142f8ceeVirustotal results 28.81% Quakbot
2023-05-17Bpqbslx.jsjs 1f3d3d34fcd02bfbd9eba7becc4eb01342dffb209af4971f9df25374411cd1a7n/a Quakbot
2023-05-17Gtchz.jsjs b246dc6bd29b7f7bf62fa6cfdb10a17053bed892c03b79d0328d384cf96f799an/a 
2023-05-17Wypit.jsjs 6bb7a104fe821f46f0853eb826d375aefd2c29fca71738cc3494e5cd9ad1c40dVirustotal results 30.00% Quakbot
2023-05-17Sepzwyg.jsjs 2c402bf5ac40a8110c89bcf0f4ccd617ba22f8e8a6ca32d9949461c82540e48aVirustotal results 28.81% Quakbot
2023-05-17Odvywee.jsjs 043c810fd7d77672928841fc44891531ce536c6b4cfb9a4e54529c20b36eecd2Virustotal results 30.51% 
2023-05-17Feihmn.jsjs 77c78781fbf40291d31c545dd06a094505a49bd415cbeed6b922cafc6af07586n/a Quakbot
2023-05-17Swkf.jsjs ecb53b7bd1821908e3358a50f35b5cc1aa92c43f7c190eaa7e0e473ca199dfa6n/a Quakbot
2023-05-17Sdfojl.jsjs d9c67f9654d7553a2a17ef5dcc074678636aa557c8130bf4f4b8b14e58830f09n/a Quakbot
2023-05-17Quoenm.jsjs 88614208bb0046aec80542086f1e7ca1dae0dbd8af7390ec1ed08b326a30c93cn/a Quakbot
2023-05-17Mndn.jsjs a55b4b945801f99744bfd9249e73a61bd9a6f20915ece58cff8313ff1e1756edn/a Quakbot
2023-05-17Diobpemv.jsjs 834b521858b951a3def97d98340f70b6659a670cceaa486bb8e08a79ebd6f88fn/a Quakbot
2023-05-17Ckqc.jsjs 123240f35c01644a74bde16b105ccd56924a899cb4f9142469c41a8f54d49b9fn/a Quakbot
2023-05-17Uptivon.jsjs b903e00b4f16c706ff3d2121d0924bd42fd790f1d426229a041d3cee6346214bn/a Quakbot
2023-05-16Pqimykam.jsjs 4da2bcd6e2909fcfee3e1ab176f8c5eeac84cf266d703cb8b54bd26d0f8db910n/a Quakbot
2023-05-16Kcffdxqf.jsjs b2902788ede583d9bb7c6ce2066079ce5e3033b38fb1073af46ef4e5ba476f92n/a Quakbot
2023-05-16Lmbip.jsjs 1119cffcdf2cfbc044007d96a287baf9f1929e8475f0cc92eb23f77cffcbcd00n/a Quakbot
2023-05-16Bdfj.jsjs aafe1c3863b2c7829bb93896614cd1a75dbfb65703210210074b8b3dd200c9bfn/a 
2023-05-16Trokif.jsjs 0e60a3b24a74bfe95eebe179f7fa530117208eb3cd06a1af43875c215bcdf832n/a 
2023-05-16Dgzj.jsjs 51bc82d10d69b9dc46b4274a1f95b736b91fadcc81afe5d47d1e423bd0807d22n/a Quakbot
2023-05-16Cvkkaqo.jsjs 2a15f3eec60c984ec17b4abd748658f4f88eb7d875c0e41f17ab6feb7cabec99n/a Quakbot
2023-05-16Nozmbiwk.jsjs 318a2a00d07afbce34d91f0b2e99fef4376dc3ea3c011bd05c458652dbf163b5n/a Quakbot