URLhaus Database

You are currently viewing the URLhaus database entry for https://jpantigabut.com/rsa/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634022
URL: https://jpantigabut.com/rsa/?1
URL Status:Offline
Host: jpantigabut.com
Date added:2023-05-16 13:14:56 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:17 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 8 hours, 8 minutes Poor (down since 2023-05-18 21:26:34 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Wefl.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Aqku.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Hnbzc.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Wvfgi.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Uuaaktcl.jsjs 2a639bb3de1a2b55b3aa1f896c63cb03ab74688d28a9e1e811a87fe2dbd2239en/a 
2023-05-18Wctq.jsjs e6473de8eb0f10d14a04ffbd68eec65c5efe6755a2bca86fa2fce1a0f317a9c3n/a Quakbot
2023-05-18Fsxg.jsjs fa4e13a9e0315137813bc3fcecc4a2ea7b145377cfb5cdd4d412a5b2256be037Virustotal results 27.12% Quakbot
2023-05-18Kkdpr.jsjs 6f741f3bd19d3433e0618cd31b85f73aa09fb1dfe670c9e5a8e0ec01cf274495n/a Quakbot
2023-05-18Cuffqly.jsjs fe6c3afc81fba017285089bb2240464e993b83edbf51755fe47e70d5ce454558Virustotal results 22.64% Quakbot
2023-05-18Gohddi.jsjs 27544c60ff36a51e0dae2573402a63de5c6ae28c1c7160377a0d3787272d74bbn/a Quakbot
2023-05-18Heria.jsjs 92541d594f60bdb46e24073e3720e0deb32a8bb5a4409a44b650b790dbeda309n/a Quakbot
2023-05-18Nohaysmf.jsjs 51351bc77c5c23de367e4fdd74a87fd4ea6a100dd396c2f78dde57c715543f3dVirustotal results 27.12% Quakbot
2023-05-18Ujwira.jsjs 288d425513bcbc2368880669d2eb2f2b553edb8962acfb77e4a967d751235520n/a Quakbot
2023-05-17Eiswcpg.jsjs 36032c143a4485946e82aa6aab03ac420e5589d6c74224bd71b3b6bc62b6dfecVirustotal results 27.12% 
2023-05-17Tdfmfdrw.jsjs c6712a15900f7986ac9ad350dec34f50284b50e708bdeb42e320d99659f8d46fn/a Quakbot
2023-05-17Hlicqjw.jsjs e1f86c377a5fb822c6704735ae1fc4f80bddbea822ee597fe99762e575e05ba2Virustotal results 25.86% Quakbot
2023-05-17Ptrlbj.jsjs c6acb46e483e7792474a50acd3a7ad70626f538da57050c7153b3061376b4f02n/a Quakbot
2023-05-17Gprm.jsjs f65cfd45df99f110dd5e24acdcb4a032a333c2d5f289d2867feb0d7fc6aa1960n/a Quakbot
2023-05-17Mbzjg.jsjs 6003ec795de91a5d5a9a9abb15e037b5f4dcd8cbf43bac5330005fdda61c603an/a Quakbot
2023-05-17Hiwdpnfx.jsjs 716b277dffdcf3099c8c86e0198ddab7a5d55627de582e5b73e900db63fed67en/a 
2023-05-17Sebxaf.jsjs b8c5cadc518dd896a78fd2a6117c780bf8260123c3d53b6e2a1253983cabfd1dn/a Quakbot
2023-05-17Bzqa.jsjs 3c55e6ac3c8be2f9db204dd96e19798e7a84972f1726a5573a2bb25b033505cbn/a Quakbot
2023-05-17Euxdoas.jsjs b0c17ba0591e6282a9adf0184abe2498c3c3d91a9cff4e595cce9b3e32d83180n/a Quakbot
2023-05-17Bfxanlue.jsjs b7344f6ad1002fa69fc1b5ac7fad89de66afb73e2f842e176b13d09acdb18518n/a Quakbot
2023-05-17Tpxfoedg.jsjs ed4fcba429a240699e5812ccb0a2b223e2f52babb474dbbdd2faef78505964d3n/a Quakbot
2023-05-17Ntww.jsjs 6b663b399597d40f5e6933bd65a661ba3a07362496d697187ca2cbb989ec91acn/a 
2023-05-17Tcwd.jsjs e5b4a08af2e1f5ba6f7c07f19572f31161ad71fab5982836eea5d43d6c462dbdn/a Quakbot
2023-05-16Plbk.jsjs d3bcecedbafcc5a6861a77ce37515af66881504d6a1cf728bb210c94b669bfden/a 
2023-05-16Nhdco.jsjs e74230e3687f2980bc6cca4f2cb7351ea6f5572bfd5a1972479acd78879ddf86n/a Quakbot
2023-05-16Pfvqc.jsjs 204e57223b76da1d47f03a8b3bf3865298050d248e241d4f3442ec79e408c376n/a Quakbot
2023-05-16Gsloqeg.jsjs c440957c4d56a571dac86e81d7faea2ab9b9688132bbb648cb7f1b7c8a263551n/a Quakbot
2023-05-16Uafhe.jsjs 35c54a984bc434b04e5e746156ec0ee8a72f310699d02d409fc196baaaacce66n/a Quakbot
2023-05-16Geyricq.jsjs 4f4b5c00e174c881606856ca71c6f15cfb80def34544be363486348ffbfa02f3n/a 
2023-05-16Eogbm.jsjs 9ecc7d38318d83593f04715deef00980fb799cd0dd6f533ff2b8ece8ce1f457cn/a Quakbot