URLhaus Database

You are currently viewing the URLhaus database entry for https://usapva.com/taur/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633964
URL: https://usapva.com/taur/?1
URL Status:Offline
Host: usapva.com
Date added:2023-05-16 13:14:41 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:17:12 UTC to abuse{at}hivelocity[dot]net)
Takedown time:2 days, 9 hours, 18 minutes Poor (down since 2023-05-18 22:35:46 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Vkhylb.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Fustmvu.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Nzgwet.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Njdm.jsjs 0f1a9d40a28989681e377a40de08093911c216783a1788f50b87d223949c1ab5n/a 
2023-05-18Xdhzxx.jsjs 01672a280309027a623a8946df0c51aec85b628ea24b9811922ab69f6420911fn/a 
2023-05-18Madtkikj.jsjs 023250d4f9af49d2f7968647280c712aff55b6146a5a06b7b302bab288a405baVirustotal results 29.31% Quakbot
2023-05-18Qatths.jsjs 215820e48ebfa9dbcba7260a2176ccbb21df119cff17a8389f165811c8e3664bVirustotal results 31.03% Quakbot
2023-05-18Ksskl.jsjs 176082ec2166a938b76477a4d42d940987b38d787c43628c9e17e75057338dc2Virustotal results 10.17% Quakbot
2023-05-18Udco.jsjs 36c1b7c7a1b5c11ac465725f40b235b232adb02f122a1d9d3210656cacf4ee3fVirustotal results 25.42% Quakbot
2023-05-18Xvvvcip.jsjs 555220330c615686c8a042f7d99f74d150a132b4d580ce95d1a7b6db412b77eaVirustotal results 27.12% Quakbot
2023-05-18Aaxy.jsjs b4a90889250c70642150c7b822ece35979290cb3664a5f778ccb8195b4c440ecVirustotal results 25.42% Quakbot
2023-05-18Btnkxw.jsjs 8116e7914df0a4fae9adad12da668660206754557fac016131c53fcd305d537fVirustotal results 32.69% Quakbot
2023-05-17Qjvan.jsjs 2b2ddaf766a72a62c3247e520317d64f6b32231d8802b99b861cdbcd872a7ef0Virustotal results 27.12% Quakbot
2023-05-17Jzdxp.jsjs 1c70b83f5b4051ac542278897c3b02f334291507f01f685e95893c574241e6b2n/a Quakbot
2023-05-17Jmwm.jsjs ca42f27ebd7d4d5472c9652e26b5cd7d9f089e838ea85a8ac5f1c51b37e83e30n/a Quakbot
2023-05-17Uzcldr.jsjs 26bcf4ed38ca973b884b3322675bbd0b590533240961f9fd6272fa3e3aeba113Virustotal results 31.03% Quakbot
2023-05-17Zoapdxt.jsjs 1539b3e778af6f644e932c0910705fec144fe2bbef2f8df241b0d4bb821d0fc5n/a 
2023-05-17Gtopges.jsjs 8f29c702a43f99c1cfc18167ff61035ac4068757aba92e0eb5e9dde5ad72a0cdn/a Quakbot
2023-05-17Xitqvg.jsjs b3c3f0880fe1ebd5b9f5146a8164da0834ee29a37e5a1cd8e534efe15c786daen/a Quakbot
2023-05-17Ubesiz.jsjs 0ee290ee4584c7cd0e33378274ef9a6cfba170c989324a62a2843028e8da2069n/a 
2023-05-17Crqqhnwg.jsjs 685deeb50e93ed27a3c9fbb5cdb1b3d0282c0a572e431be75123e27ddee8ff89n/a Quakbot
2023-05-17Iepuo.jsjs 03823e4272ab8a368b36fcc95217140ca825ec8136c2f8600d188f991cbe9b85n/a Quakbot
2023-05-17Dcvsbyyg.jsjs 678c75a54178c63899b3b0d68808c2d6024a2cc76b4b8eadcdc6c336fe736515n/a 
2023-05-17Jyrpc.jsjs 35efe6f51f25ad9dac34169c390346c56a73d293760a96aeb2ec321aafef855bn/a Quakbot
2023-05-17Igcmaa.jsjs 40b7075136a8e7cf5deea8dbfbf2c864ee05d3c38fb90622da5a515ab503a9f3n/a Quakbot
2023-05-17Jyxg.jsjs 120cfde3ab1dc08e8501ca17f531736f23c26bd79b1e272aa33c8f193595dc99n/a Quakbot
2023-05-17Vpmjxc.jsjs bbcd0e6322b1381e18659a8ae3a4590023e2ec3873681f07a20f212c77d0fa7bn/a Quakbot
2023-05-17Xvdc.jsjs 75855b0a9ec205d4fc9ac5c9da6266ee07d53dc35899f4a82bac3d490fb8c915n/a Quakbot
2023-05-16Ngdzwkc.jsjs 4f7d99426e872d4535bf581bf730055dba040fb8d0ee2ef6337391fd68b8b8cbn/a 
2023-05-16Tnuv.jsjs b10f9a5fb3a148df7bd38384070be9a42870923139b16e3cd29a541c50ffe797n/a 
2023-05-16Sxuvzwo.jsjs 7ce55d2d2b6ad66f702060b55863c8b2f2b0869248fb6d3b1c55bd80a6165d74n/a Quakbot
2023-05-16Nwrorx.jsjs dfe0e7852681cb391555284da8339fa043e4232ca858493692811c6257d9eaf1n/a Quakbot
2023-05-16Wegmx.jsjs a0c86b5c6b43479ca0f22ed015379e46a72703bb40ab094d5e3952ecb5bddf82n/a Quakbot
2023-05-16Avyeosl.jsjs ba4e594f5660f47e5c7fad25fd410f03044da21437713e0bb3a271542232c11en/a Quakbot