URLhaus Database

You are currently viewing the URLhaus database entry for https://teddrealty.com/er/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633974
URL: https://teddrealty.com/er/?1
URL Status:Offline
Host: teddrealty.com
Date added:2023-05-16 13:14:45 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:17:24 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 8 hours, 4 minutes Poor (down since 2023-05-18 21:21:50 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lefqpts.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Gsvz.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Iopjurh.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Yulf.jsjs 65e402748a18851479b75d5689a7d84f47994f0d86e272949c2b270d1cb7ce51n/a 
2023-05-18Ykxeo.jsjs 5c02cc26158109b9e14b2601be5848cda11477e56c521a791dfdc4081366da0bVirustotal results 26.67% Quakbot
2023-05-18Rihnxnb.jsjs 874c90fd9f5dbc042d5e87dee75b68570376e628600a8d08dc1083545283052eVirustotal results 27.27% Quakbot
2023-05-18Jiqegz.jsjs e29a41a9d60625c8b7ab2e66896cd279af26a9abe095095e8f71d39a518717dbn/a 
2023-05-18Dfjvo.jsjs 029b6f2d9cfb0a2a335c9b9377c1dac9e71206e55f6f82c7d3c0e2edceb9b734n/a 
2023-05-18Ajhqfc.jsjs 0204463c040334db593942c0e48063d6f6df33cbfba1fdbf8bfe51aa0bf83372Virustotal results 27.59% Quakbot
2023-05-18Rguttq.jsjs 98ca0fd1f80c8b41e2782376e1e44d8dbd142e3c6e7f91e3459aed684bf210a2Virustotal results 25.86% Quakbot
2023-05-18Dxfftof.jsjs e78861a712a577b61558f7ea9878b91e974692081e5daa5f02dcb5ff1cdc359aVirustotal results 32.20% Quakbot
2023-05-18Pfvxjxjp.jsjs 506d6f7370fc1f1367a79bb76a39e5ed1e2c5113ca286350f3239788538fa80bVirustotal results 25.42% Quakbot
2023-05-18Rufbd.jsjs c419bc2833e48f8f26166ef911d3915be8fd0619ac6a0e0638813a4404df6979Virustotal results 25.42% 
2023-05-17Ftaga.jsjs b65cfc5c1f188f590ab7d7d6a20d1ea638a086a9be61e3442b6ea9388fda3c0cn/a Quakbot
2023-05-17Wwmmi.jsjs 8f547a495bc6e319219b5db2491f70ce4792f76b7770226d37be2b28fa5f79ceVirustotal results 27.59% Quakbot
2023-05-17Uotip.jsjs 38158794f34f920ddf3cc1bd5048a2d8be22b550ea27c09a0c746d59e22b3fc6Virustotal results 32.20% Quakbot
2023-05-17Xtsvhlk.jsjs 4aa5f66645ca2168af894232b630df6e88077c51f4fa33cbe2efd094e057fd02n/a 
2023-05-17Dcohs.jsjs 66a44d6ecc0bff8550c4f8fd93b40851e019bac6297339dd180d268ed9bba451n/a 
2023-05-17Ldyqm.jsjs 9459a0cb6bc3dff0f7972ac6852fb2f11dace3df33eded8be946a0ca5f1160d7n/a Quakbot
2023-05-17Jfmimpa.jsjs f6f59e8aa77d83d38c5944434c0549f1a115369e8acd5f6367a02689c880fffdn/a Quakbot
2023-05-17Atnhx.jsjs 707a6552fc56054ede40279161837a0a4987efda3e0c3306149a2a2158e27acan/a 
2023-05-17Aedb.jsjs 0635349d02945a2f759ec6849dc651d5a0fe8948561812919b5108e16b0d1824n/a Quakbot
2023-05-17Cmpqigg.jsjs aef200e47b616111d144c7c0296ab0549861e6b6a9d1052c32c62077b2b94556n/a Quakbot
2023-05-17Lwhtwbnq.jsjs efe6b2a252c2ae773934b170f64f921548d238bf08e4318d20795eb9a17d2d24n/a 
2023-05-17Msmhbpqr.jsjs bb50229658806172fd55f886b9a5e6c5b29f74d1db85a095071d89d9d4cf3237n/a Quakbot
2023-05-16Rymjmriq.jsjs 21ff89bfd36db88e4d7bb20210f632ef089ba526ddc0414647d67c24c05aa5ben/a 
2023-05-16Kzjsoy.jsjs ae028969d2c5a7de5d8fb96d9e21de37e8a9625791b32f7f6be4d419db633660n/a Quakbot
2023-05-16Odzdayxk.jsjs 6ba84821ac2d6696974d41d6153bba2489df02d33feca014a03054f91a663909n/a Quakbot
2023-05-16Ygzrprso.jsjs 536a282ee0637245e6cc41ea0cc1d89f3938d14a05e09a08d83c82814611495bn/a Quakbot
2023-05-16Brpm.jsjs 00391b82e903a525b967253e762a9c1037b15b7fb0a4683b3c7c199a6e3523bcn/a 
2023-05-16Eufmnr.jsjs a9032fd02ab13ae8dc7241335f2098c6b7f3055462128d27e24747db94d69206n/a 
2023-05-16Gekvx.jsjs c987ab407d5ec99e00d1e8831a5d81ffc92edb38cbb29014a18d983b51e2ea5an/a Quakbot
2023-05-16Wcgc.jsjs aa46193f804603dbee21c1231b561a05569f838a335b15f6dcb7e602231f03ean/a Quakbot