URLhaus Database

You are currently viewing the URLhaus database entry for https://harrogatevault.com/ni/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633972
URL: https://harrogatevault.com/ni/?1
URL Status:Offline
Host: harrogatevault.com
Date added:2023-05-16 13:14:44 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:17:21 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 9 hours, 28 minutes Poor (down since 2023-05-18 22:45:37 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Rsdcovz.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Klsujceb.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Madkmw.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Dptyby.jsjs 1a6cd7421bb07849528be616506b7daad7114d085d4e65a402af0ba9bbb6924cn/a 
2023-05-18Mmdnfahn.jsjs 3bc2c76bd30c4f67c56425ecd3201a7bd43655778be5fee4b7a2f72478c57d5fVirustotal results 26.67% Quakbot
2023-05-18Lhxie.jsjs 6e98b0ad9b6fe81e7dde4a5e76cddfdc25b19695ca702e4faf95f45dfc5a65e4Virustotal results 11.86% 
2023-05-18Dzpdu.jsjs 78a09834bde88bcf04dd934a793540b810b090e90efb96a977c2477be294fc75n/a Quakbot
2023-05-18Htoges.jsjs 397ed6d5f113de3b5a638878e1ab22bb58f5fb493aaef92441db571bcb4c81b5n/a 
2023-05-18Uxgkgf.jsjs e2334bf18981148d6120cbe4ab94a09cd0bb833ae95e71955079aadd6cfc720dn/a Quakbot
2023-05-18Pbjnw.jsjs d2087d9119d773d88b9ed612b2300de62865eab8a6dfbab02955c20d0bd11582n/a Quakbot
2023-05-18Bijk.jsjs a5f3d5a1dd9f57238b6a528792a0d6043f93289be9f4e2760c3549006c132bf8n/a Quakbot
2023-05-18Sidjdotr.jsjs 321c1a3f14a23d2a9aa660e3c3d41d7c92fbba4788fc20057ac697e402248405n/a Quakbot
2023-05-18Dikths.jsjs a84a8c5338c73e889cff9d58c510657f8624b8deedf847eef71befacab5ed60eVirustotal results 20.00% Quakbot
2023-05-17Ijig.jsjs 6bb7a104fe821f46f0853eb826d375aefd2c29fca71738cc3494e5cd9ad1c40dVirustotal results 30.00% Quakbot
2023-05-17Ebpcxdiv.jsjs f093b882b8fd4a20a6b626c96af959ed31285d4cd57354e4cf7de124fb062b81Virustotal results 30.51% Quakbot
2023-05-17Noimp.jsjs d7ee80c4c9f9a041e63b9e4a454dfa6c60dcb7fdd18ca658f2f92fc97f61d766Virustotal results 22.81% Quakbot
2023-05-17Uvlqdv.jsjs e8f221308008303d546d565fcb2601b794a95ce83d609f81b4629c5284a8547aVirustotal results 24.14% Quakbot
2023-05-17Qvqmnino.jsjs 245d8b4566da1f99cc5bba4998955421b38764ee0718c94a6fe8019674ccfcd1n/a Quakbot
2023-05-17Dztlxq.jsjs 02736e3801e700601d6212804b2d824ae4771d32fb369044887fdc9f2076ddfdn/a 
2023-05-17Vachko.jsjs e83bd9c4b21fcd0dac063c512259b7310762d0f7b923cba778206403e5314398n/a Quakbot
2023-05-17Oiwckum.jsjs 3c69801d0a1306e6cf887789547e438ec9754d4760af951b17239b057e2e3da6n/a 
2023-05-17Xffbhhj.jsjs 9fcba6f8fc6574787765792eb0545faac5cdd2327047890e01c62aa314c2a69dn/a Quakbot
2023-05-17Dgxaail.jsjs b3f301bcc5096d7757f081c9613cc1edab73424b25267e077d1e6c8b8744d0cbn/a 
2023-05-17Xynqe.jsjs 05b19b7e889785d21f52c7b4dfb4a8dba61ecd4b763f35aa1fa23e36c4061055n/a 
2023-05-17Jvbxon.jsjs f2d6b3c64ee8286e5ed122a00ee56da22ec79644093196ebc41960483911e6cen/a Quakbot
2023-05-17Gjvz.jsjs c0cba98eab1b593edbbfb843416ea0461f5264a922344b951b5c511ff91b3cc8n/a Quakbot
2023-05-16Sxbq.jsjs ad10e862fd0d194f82aa3d13214ac8fe66c7fa2fd329c661ee4671a428843d77n/a Quakbot
2023-05-16Aevld.jsjs 21d195145fb467e9bffbf544b8a14b56e5ba559e147eb5b3d36b4ea390ef22c8n/a 
2023-05-16Ulnm.jsjs 7448600ee83f43e44ea68afc5e609f20b9ae89ad704c92cfa7a4e55f2f385336n/a Quakbot
2023-05-16Rlfmlsub.jsjs a85dccd54028d62b15f509f630d93d11beeebc33392fc7b63634bbd4188ad405n/a 
2023-05-16Abbyfr.jsjs b440f3b1f231d74e2cecea1d2607e123fc233f1b73ea3352b2446f1489b14fbbn/a Quakbot
2023-05-16Lxmgphm.jsjs d2bac6956cd4c4c7d11b2c5713d1972f23215864b75632529b92971f153236b1n/a Quakbot
2023-05-16Vhmve.jsjs eb3bce75b4a89f4b68839e6d4129ddcbff6d4b53720b48f0ea58fde3e12b0b58n/a Quakbot
2023-05-16Hhjv.jsjs b024f246e798ba4ec8bb5cf60a93c12d1b77d770dc2a53f6da8e53875abbd780n/a