URLhaus Database

You are currently viewing the URLhaus database entry for https://greenreset.com/lira/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633993
URL: https://greenreset.com/lira/?1
URL Status:Offline
Host: greenreset.com
Date added:2023-05-16 13:14:49 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:17:43 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 7 hours, 43 minutes Poor (down since 2023-05-18 21:01:14 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Wnzg.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Rrvkiojc.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Wyjdwuk.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Gjrc.jsjs 6a23cf1558f0a3efb0abb0f298f9716be0446165e859f1116485a847cf57442eVirustotal results 32.20% Quakbot
2023-05-18Fqkfnu.jsjs c3b7288bc652fda94fb09ac95870f66d2e355b6637b09d5c9fd1b7d64d660a52Virustotal results 25.86% 
2023-05-18Qoiuwhhh.jsjs 6f1a5f81c661643e1367ba7f42de50ede7d8841c0eb4bd7e13f5922b8a539766Virustotal results 29.31% Quakbot
2023-05-18Caoi.jsjs 0204463c040334db593942c0e48063d6f6df33cbfba1fdbf8bfe51aa0bf83372Virustotal results 27.59% Quakbot
2023-05-18Xqea.jsjs f21a9095152b5a7124af37bde4000f76717ad002ec5e40bb2b86dc71839dabeaVirustotal results 30.51% Quakbot
2023-05-18Xczhixxt.jsjs 15284b1502dbf4c84ff0c772b1ae8788a56987a2e9cda8ba27208e57da59e8a0n/a Quakbot
2023-05-18Tmiff.jsjs 33f33ebc5ae78bdbf3a9afc064c64f1121c0214e1305d5567232cbc8779ab8c3n/a Quakbot
2023-05-18Enbmpn.jsjs 88c9cde337f3a1dcaac0cf20b1b30b985ee5b11e0bd60b3b768a3f70751105f9Virustotal results 32.20% Quakbot
2023-05-18Lccu.jsjs c7164e6f2a5f4d34a5877e5de94ba49af13d9b6e10be7158adc9e0d267084c28n/a Quakbot
2023-05-17Gypy.jsjs b95a6f4518de9f894317d0fe03a9dbf1132ea5b5053e9f11d63ac0746afde62bn/a Quakbot
2023-05-17Moec.jsjs f15cee857739e493f0b99f7ec002e9fd76dd37b87080807a922a414a5294c989n/a 
2023-05-17Zkvoc.jsjs 47831ca3235332c96696b1add7425b7dcb044b9de06934992957a5e00cb4dadcVirustotal results 25.42% Quakbot
2023-05-17Rtaqhmk.jsjs dc0d873178c61dae13dac14d65611d4716e9c28ebfa216e32126dbdd1ac971ben/a Quakbot
2023-05-17Snzeim.jsjs 611f39b0fe3d00c6bc886929f93aab5028192d0d7398bd8621b700c05e99dcc9Virustotal results 25.86% 
2023-05-17Drvolmto.jsjs ccfd3d544f060b0b45133acf8df8a753724ec29a916820e53f6e7692dd785c8dVirustotal results 21.67% Quakbot
2023-05-17Hfiq.jsjs 7d4c05f2b21fe02c34ffc3bc7077929482fa7cdbc01c894e2647cf6e38ab20bbn/a Quakbot
2023-05-17Jmvc.jsjs e617080accb2d844338679deed9c4b07675ce4fbadf5f6cc641eb9c7b80b7c4fn/a 
2023-05-17Eqyrtvmm.jsjs 7ccdfb510c20ad897a0920d6b13d3f8b953f414ca45312a1abd71771014f85f6n/a 
2023-05-17Enmccb.jsjs b85f4cbc32935af1221a6439a7616310e3b5925fd829a557686a6631c8efc842n/a Quakbot
2023-05-17Awctxpw.jsjs 3f92d24fc938ee2f3fe8096d31d5a22d88f04fad13c1f27de8dadf7c97f51acbn/a Quakbot
2023-05-17Xskfshfs.jsjs 99d777be7c86fcf15dba9a0d8c0559c548f5c59e128fd21fbb9c60824140b957n/a Quakbot
2023-05-17Zwgtbfy.jsjs 1c78d33a15cbae51c7fb0c3a77733f06c133d5c8b7854bf352413910d5a0580fn/a Quakbot
2023-05-17Avgoors.jsjs a85e945b4c1479f3d4d12503ea2f2095351fd859313267d78fb877e9e852b888n/a 
2023-05-16Gzomrvt.jsjs 4235b80b7f718466df3ffb5a7f428f10d874e7ee3b795a8d33de21fa00ee61cdn/a Quakbot
2023-05-16Lnsaftc.jsjs 0f900c25535f0874bcdd6b7757b14b883840f72566bcc39144d0e1c1aec8d58dn/a 
2023-05-16Zniz.jsjs 62d9a1a63347d89802364bb1c755abc0a6d2eb7d3cf5502241396ac12e514235n/a Quakbot
2023-05-16Dqzbgl.jsjs 483cbd6fc878891b5da9595eb01bdf96d044a0f3bbc869ac5e7e727f65fe111cn/a Quakbot
2023-05-16Mxjdfg.jsjs 88eac8e46d8077fbc35d1f2a4bab0693079f513dac672a9622493778c5576ddcn/a Quakbot
2023-05-16Hzufym.jsjs 8bc316345d7394e470be40c51f88aab4fcfa0a2623e0b588a3707e402bc1d0d8n/a Quakbot
2023-05-16Ualopolj.jsjs 623ebcb3411ea2e5ea7a1ca5ab7eef9f844c88eaa3d7e970ada21801187e22e7n/a Quakbot