URLhaus Database

You are currently viewing the URLhaus database entry for https://megademi.com/ini/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633982
URL: https://megademi.com/ini/?1
URL Status:Offline
Host: megademi.com
Date added:2023-05-16 13:14:46 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:17:32 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 9 hours, 34 minutes Poor (down since 2023-05-18 22:51:33 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qzap.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Dotqe.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Zpsiizxh.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Stqurjw.jsjs b791c6fe50d67be4051d4695a898a67c06a3f28be8fa9f0ba290db28c8362905n/a 
2023-05-18Cwkpvsm.jsjs b246dc6bd29b7f7bf62fa6cfdb10a17053bed892c03b79d0328d384cf96f799an/a 
2023-05-18Oxykzq.jsjs 6a23cf1558f0a3efb0abb0f298f9716be0446165e859f1116485a847cf57442eVirustotal results 32.20% Quakbot
2023-05-18Gskyof.jsjs a3b99e8c39ad9b207f02de2422a94864986aae304adc635dc0cda1b27ac9e322n/a 
2023-05-18Kwglvp.jsjs fd0ca1aeb929c31a64a1ec9c5027c0c2c644161a6fe7faacf6ea8ec30ca8806an/a Quakbot
2023-05-18Ewop.jsjs 43f0a123b00abe19f1412b6fff2944e5bf4436a2ba20e3493ba9708ee5088c8bVirustotal results 24.14% Quakbot
2023-05-18Zddq.jsjs 02caaf8685c239c1d2e1a5e8440a7c9b39c4b12921ba12cfce6caf0214ea2df6Virustotal results 15.25% Quakbot
2023-05-18Htvfwc.jsjs 19add01de5eb9fa85d7bed9badc8daf24f0083faf06b7eaecd8b1efb21be5428Virustotal results 25.42% Quakbot
2023-05-18Ixzjlw.jsjs 269dec903e55df2babe1cb8bb498ac7fe56d2a079cdf89c2d5c354b7a8fa1250n/a Quakbot
2023-05-17Yeopiqwd.jsjs 614b789451a47511f7b28865dc84ac5a5214ce91e53b5f9ebf50cc64c5cff4d0Virustotal results 25.42% Quakbot
2023-05-17Ylrklb.jsjs b896df419a5e1ac8fe67ede2b9594d6252e8dbf87ef64fd093ceacc52a84798fVirustotal results 24.14% Quakbot
2023-05-17Eayulkpt.jsjs 2810143d11f9ad7077972f807f2dc04a3f22746f81b7d8365d879e722c0b3551Virustotal results 17.24% Quakbot
2023-05-17Ckwice.jsjs d953d8ab979233a6b29a964f031086bd74ed7eb684d99d10f5a881778f4d13b2Virustotal results 27.12% Quakbot
2023-05-17Lgdj.jsjs 6c2bc2e984886cdc84fd988cc8504fd8737f22afe09cd972d52344c526d16d5bVirustotal results 30.51% Quakbot
2023-05-17Volqfi.jsjs 3b413252866f0b4261ccf3b4972d86690f29353242c85733133be84940ad6fa3n/a 
2023-05-17Qift.jsjs c7164e6f2a5f4d34a5877e5de94ba49af13d9b6e10be7158adc9e0d267084c28n/a Quakbot
2023-05-17Hxmkub.jsjs def1eebe55f3bc428d1f39ef2f6c7d61a64a48dcc71389a348eefbb797e07653n/a 
2023-05-17Vhcb.jsjs 3e188e282a952a25bf310323b261ce2ffd4bf23836d0d8087fc9c4da1f4180ffn/a Quakbot
2023-05-17Gqlgokea.jsjs 872c0540e3f5571c6c3b641167031b6b1921c40341547cdcaaabb0368297590cn/a Quakbot
2023-05-17Oophq.jsjs 840dfb99af8fdf7fdea3ed64000a5ac56a1e6be893b2af87fc609b56fad66b09n/a Quakbot
2023-05-17Cujg.jsjs 647d523c36622c9de65e353a11bb51443bceda6355410e2d71426a3e7fe2102fn/a 
2023-05-17Leqs.jsjs 5e17ebfc22c1efd62580051c9bcfd32a07d7c378274da67b71ce45c733e62539n/a Quakbot
2023-05-17Ccjexml.jsjs 66c0a50d339304d1e32940d3b4d51680780f8b73396a585ba01e6d71ab9ff59an/a 
2023-05-17Cuylokz.jsjs e2a5f918394f148f775373c4e3b65d2eea30af0f84163955d4c33eaf4174f68en/a Quakbot
2023-05-16Hkrkzk.jsjs e3e7737629a4df2d15051ccd3aa88a4a534d464293d0a8027c468877b93a0e0fn/a 
2023-05-16Hafac.jsjs 2dabee605cfd825efad3bc1d7e7e8b502bec866262b7200796eee206fb992eb5n/a Quakbot
2023-05-16Nxem.jsjs 4147a794ce4f31d89a142e37b7e6e080dc238c91a50a3079d3940fa6f83f8d67n/a 
2023-05-16Ugkt.jsjs 8e66f85e74888ecfb12011f0e81942a21532d104191f28e9c263c0f7cda7058dn/a Quakbot
2023-05-16Nrbhnp.jsjs 0212f484dec5c3c305296501de82acc00fbef07129a6c85b61a826d2f95a81f3n/a Quakbot
2023-05-16Kenuhycr.jsjs 28bee21ea05de79c67d11517371c04bb237991283d2c065466c7c2dd1f0760e5n/a Quakbot
2023-05-16Gpmh.jsjs f640f210424a7cf551481e6aeff3f1e9ee3d292242281c9823c8e91e8288a556n/a Quakbot