URLhaus Database

You are currently viewing the URLhaus database entry for https://medicaretrainingonline.com/qiuo/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634023
URL: https://medicaretrainingonline.com/qiuo/?1
URL Status:Offline
Host: medicaretrainingonline.com
Date added:2023-05-16 13:14:57 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:18 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 8 hours, 24 minutes Poor (down since 2023-05-18 21:42:44 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ejln.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Nnmb.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Eyrcb.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Umtl.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Mddo.jsjs a8bb61810435eb1076f718e186e18910d203a2a14678c379b326d4efb572d343n/a 
2023-05-18Lossp.jsjs 9da26f54018ef7b69e7ca172d1ef9d1de643acee030e0b25c66a5f27867c8833Virustotal results 26.67% Quakbot
2023-05-18Nxfzlvnb.jsjs fbf34d1f59eea01ae0ec44fb3d7e93d4a06dad0b411065a5d6292f3ebe7081acn/a Quakbot
2023-05-18Ajla.jsjs 2810143d11f9ad7077972f807f2dc04a3f22746f81b7d8365d879e722c0b3551Virustotal results 17.24% Quakbot
2023-05-18Lfpdid.jsjs b89d6433da85e8b53b60dd8f31aa096c923d9b4fb337c03d3b381482ef280974n/a Quakbot
2023-05-18Oheq.jsjs 24c2f222f6f2809f7c5dda15d789a41d9424dfce3714fe71bed9fbb0e077503en/a Quakbot
2023-05-18Qpdtue.jsjs 07b159de000e3d081a5de88077364dcaec1eff528f38b286c7ba65059429853bn/a Quakbot
2023-05-18Yvilczsm.jsjs e7958ccd8a002219ae5c0a15fe85c42f33e3433270f0ba102d597f19a494e2e8Virustotal results 27.12% 
2023-05-18Knzgp.jsjs 962531faf5a4bccd1d88868db9f0b5a79c3073f110ae5e4b9f61d7ea15f8b855n/a Quakbot
2023-05-17Bwxtyzjc.jsjs 7b0e64b5b88495d402a11b16ad7776cc5e0d44a07992e8b9cf9c7006a92ac8bcn/a Quakbot
2023-05-17Ydtcnln.jsjs 5eecbea9208745932f291b3156e7036997e4b1e93f7bb53a270cae7c125aa079n/a Quakbot
2023-05-17Gjyq.jsjs 9c3ce9878a22fffcee6c677d536eef828546dc7592693cd8be968e6235ceb49fn/a Quakbot
2023-05-17Uvicow.jsjs cac584e2ff62f01ca51db682d0b6d32ff11123c3bc3b6a5e9794606ad51844fcn/a Quakbot
2023-05-17Vjkljlue.jsjs 4cfd3cea6e5aacf340993648b46bbd6628953021cc5148be665b68de39755e98Virustotal results 27.12% 
2023-05-17Nuuixos.jsjs 7a4ab56c0029ea06eceabbc4e8b9f005b37b97d1ea376ed3db95729269780e17n/a Quakbot
2023-05-17Qljxdw.jsjs 7217ae2adc382459d109d0ca1135074318d85578de92f3c231dd520402b6d647Virustotal results 27.12% Quakbot
2023-05-17Ebacoo.jsjs 1059b39013050d376b25bd3e5322f4dbcdb6956ad35207bbc2eaab4032219694n/a Quakbot
2023-05-17Syyvg.jsjs 8bd77813a32634539953361fc300deba1c844d680b7868c1d1e6a8da3d555210n/a Quakbot
2023-05-17Khjgw.jsjs 0db2dd1fae9c1fc72017cf82235991041f248babd9a14e49cbee9f8f142035acn/a Quakbot
2023-05-17Rhvej.jsjs 069fbc1100568fe5a9a6cd1f9bd315992f2adcbf2784787870aedd091b1e6196n/a Quakbot
2023-05-17Hygnmg.jsjs 6df27fbec90774e6756f1dca28f4350c1682ad90f7213669e81a814184c141e8n/a Quakbot
2023-05-17Zyhohfpc.jsjs 254a477b0cd3d5291ad99d4eeeacf0c8b5dd1ef00e917f67f9b010f1942c9857n/a Quakbot
2023-05-16Tvgulwk.jsjs 1422b9c458b8640c5dd6b52bc9264d9b92e1dbf8a94ac29bf977a5e4d4c72d3fn/a 
2023-05-16Fibeestq.jsjs f3020ad91d43fb95e2613d805064178fa978a483df796a9721f5dbf893d7d019n/a Quakbot
2023-05-16Nxryuft.jsjs b2f1f35768496845ca9a681c5fb475698c4af425c4e80074ac97c88a9427e838n/a Quakbot
2023-05-16Nzzfsdpa.jsjs ba7cf193c944ff4424418fdc127e8b032f981c79b55e14ebd7d410e3b23eb975n/a 
2023-05-16Hughegl.jsjs 055225f824a105bf8570aaf921a8ef26d5e4cfac579e3519ca9d4d404d78ecean/a 
2023-05-16Wgbzueim.jsjs ab39bef5d4db0b17d82250fe5c815a16eeb548518cc9706d2e3d68d1310d08e0n/a Quakbot
2023-05-16Lshesnc.jsjs 428aed4d161b30b4dbf7c986fcc1bc1772d3f2293a48e68c3d03e4398441a6abn/a Quakbot
2023-05-16Fztdmk.jsjs fbcb865b7dac0669c2ac7fc4cf813baeb201e51450a1118f291ba99be388df3an/a Quakbot