URLhaus Database

You are currently viewing the URLhaus database entry for https://iqonmedia.com/npuc/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633948
URL: https://iqonmedia.com/npuc/?1
URL Status:Offline
Host: iqonmedia.com
Date added:2023-05-16 13:14:37 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:16:58 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:2 days, 8 hours, 18 minutes Poor (down since 2023-05-18 21:35:28 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Gpmh.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Atgz.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Phxmi.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Rgrihxy.jsjs 33ea5b3cd871cebf5118eef971bbde4664f3e77d6bc6a2da858a6384cb54d4cen/a 
2023-05-18Qborbhg.jsjs 9d55c860ce682edea5933b6e9e441703b00b9880087fafd62ecedabf0665836dVirustotal results 32.20% Quakbot
2023-05-18Cfjx.jsjs 4aa5f66645ca2168af894232b630df6e88077c51f4fa33cbe2efd094e057fd02n/a 
2023-05-18Gysffs.jsjs 27f17e9ee4e8f78f3e02acac452da67130c961c7c0d07e9ac05fe68ed2f3c07an/a 
2023-05-18Zemxvr.jsjs 9f58336c0b0f6cde0a91dbee871cad45a315c5413863ef2b29affc9c949ee72dVirustotal results 32.20% Quakbot
2023-05-18Htmugdv.jsjs 8e028afe5e530bff241456519d98c4afe35e4e8432ca6929cb4a327144ecb765Virustotal results 29.31% Quakbot
2023-05-18Zeoqifk.jsjs abc48260d90f80894b8dce196c06da33c2c84c6e28e7f70c81840bf419cf2344n/a Quakbot
2023-05-18Nmcilcv.jsjs 5fe1ce92222b0ef2d0fe599c26907689fbeb05acb3c14dcc9cd468d2db479a26n/a Quakbot
2023-05-18Noqdmow.jsjs 5848de38e1e0698b0e24ebe9bf6c45ef062f0f7d7dd7444e4a32d6731d5802aeVirustotal results 33.90% Quakbot
2023-05-17Jswslqr.jsjs 6e98b0ad9b6fe81e7dde4a5e76cddfdc25b19695ca702e4faf95f45dfc5a65e4n/a 
2023-05-17Ykhlump.jsjs d4d054686a5e084363a71c69d138897e7b35fe3a4008cdd377ef2a2121799d11n/a Quakbot
2023-05-17Wzammbi.jsjs fcdd7c512aa91e5f6574a7c7ab77a118b9e1af5f2e3b502a5adb136508c4ba47n/a Quakbot
2023-05-17Amqour.jsjs 42046702c8332860c6d6224d63344bbd919246deac12c67a32bee542c7cde41cVirustotal results 25.86% Quakbot
2023-05-17Irchsws.jsjs 644d7490c3fe27e34ffb24eec109bfe9aaaab1a088b489de784de77611e65df8n/a Quakbot
2023-05-17Ewtvw.jsjs a99deed91507b2e0aa98b17753892aa733b12eed707f493c38359420a3a4f109n/a Quakbot
2023-05-17Ytcq.jsjs 812cc57a966264823ac9c3e7a2ec885f1ade0a4a304ac4ef12554bbf9328338an/a Quakbot
2023-05-17Zlyoz.jsjs ad4caaa604faa00cd1d9ff832b1d578ad9e97c9c06943ba647d90b52dcd7a419n/a Quakbot
2023-05-17Sxevx.jsjs a88301ae9ae3921ea75fceebd2de70c598abe8cfbfcc3e845e202980b57d0076n/a Quakbot
2023-05-17Czcxwll.jsjs 9c8a39e69844f817e68a29c28a9d1dd096c2ccebf6017009b2a49e6bd274c25fn/a Quakbot
2023-05-17Noefrx.jsjs cde720713e0d7537ec8e7c001a172364cdf217a7d22b751676698ccb3788d104n/a Quakbot
2023-05-17Rlgo.jsjs 6392ccd7ea5502d32e9bea33122029dfb222320b54651384bda4ef2973d9fdf9n/a Quakbot
2023-05-17Qbtodrrk.jsjs 5ebb4cbe477132ff9b03a842a8400cc46b0ec4a0b9ecb2499b505c4b19a9761fn/a Quakbot
2023-05-17Mjvtvc.jsjs 58424d0a16c2a5a898db1ee04ffa8f9a2a08fe0368adbb696cb4a1774cc88f97n/a 
2023-05-17Yhilimmr.jsjs df63cad7478afa662b38652048a9a52812f6d5c6449f791c63abeadc61f09992n/a Quakbot
2023-05-17Idcv.jsjs d9a7cf21843e0ab71c9560e12cad4accc658f403432e3efd0c7af60a5a75c650n/a Quakbot
2023-05-16Btfjfzta.jsjs 7cbdaf733dbc9bb85d2fea83dfa35e16dd5d3126aaf80b84137fcea32ad0f3c6n/a Quakbot
2023-05-16Ohcq.jsjs 6871c45dd3f587f75beb1230f17da7e4854181ad1041333dcac8f04254f7d002n/a 
2023-05-16Iadte.jsjs 40104773de9dea83624543145d80a1052142722a9958fd51a2554767824016b7n/a Quakbot
2023-05-16Qflndbk.jsjs a5688ac26a144982f4ff2a3f06b862d040c5b04f25dea32dd8aa2be7d8563604n/a Quakbot
2023-05-16Ydthp.jsjs 7fbb3b0c9b882ee3f35d8a739301ebfd57adbb0d4e2a26821f323282a5edd51an/a Quakbot
2023-05-16Jhbae.jsjs 31a16d30550c7f3dc53db202fc480749e94b7391316333c24025fe617d7ccaeen/a Quakbot