URLhaus Database

You are currently viewing the URLhaus database entry for https://providenceappraisal.com/epde/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634028
URL: https://providenceappraisal.com/epde/?1
URL Status:Offline
Host: providenceappraisal.com
Date added:2023-05-16 13:14:58 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:20 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 7 hours, 44 minutes Poor (down since 2023-05-18 21:02:31 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qovormut.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Jqxgecj.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Afjwktnq.jsjs ff6c86b86f00f452e357729771845d39f6e477dbb4608cefb2f95f8dac06f3c0n/a 
2023-05-18Ogicla.jsjs 73abfbef5c169e5239c78d4c04f3d18f7f72490c2ca0cbbb33d92cac9675dd16Virustotal results 27.12%Quakbot
2023-05-18Vbsoarr.jsjs 119865e21bd0f564ac17f9e36940d9360139b87392fa02dce3483f1a789ab4abVirustotal results 24.14% Quakbot
2023-05-18Nkbcgrg.jsjs de40c651da56945e6aa4f1adecf9ca842f4b2c630f3e1ad45c2c02952d4578c7n/a Quakbot
2023-05-18Ylomdm.jsjs c2c29ea19d16a1a70e365c2161d223994c0610958fe527bfcb605ed47c4a4d44Virustotal results 32.20% Quakbot
2023-05-18Lyud.jsjs f0dbb6e29c6d7e8d5463a1e716423776b0aa2be9fedbdd957adf165559ca8a5dVirustotal results 28.30% 
2023-05-18Hsyor.jsjs 1d2471f7acbab8882ea6f628275c501f0f81e0aeab5ee16537702bd849e8ba6bn/a Quakbot
2023-05-18Aheaki.jsjs 6c9b5539e5f1f1b4e1d609c95278f2b4bd4386f4efc315a332648f1467d2b94aVirustotal results 23.73% Quakbot
2023-05-18Zncbg.jsjs 3e294b83a7ced7203c04c79e0e2893c636344ba211f59ff49a66d91a93fe3bc4Virustotal results 13.56% Quakbot
2023-05-17Gxwdcid.jsjs 5284d5807da5986ffb17fdd9761066974cb34030eb5067e7f9a65e48b32f37e8n/a GuLoader
2023-05-17Sjbcoe.jsjs b65cfc5c1f188f590ab7d7d6a20d1ea638a086a9be61e3442b6ea9388fda3c0cn/a Quakbot
2023-05-17Jbeih.jsjs 15284b1502dbf4c84ff0c772b1ae8788a56987a2e9cda8ba27208e57da59e8a0n/a Quakbot
2023-05-17Zaejdb.jsjs 3c39de1cdb595f8d1822395bd3cf9c81743a1b303cf7188cf41f49bf8c0005c7Virustotal results 31.03% Quakbot
2023-05-17Glieu.jsjs 3ff223428a9d2b7b897fd823e4add6ae4cc119c86e47eb073bdbf5a578a17226Virustotal results 20.69% Quakbot
2023-05-17Rarb.jsjs 60483947f59c4a843833ac5302fae111fb318dafe639770153154f7e01c2afa9n/a 
2023-05-17Dbytbtr.jsjs 906e50a48250213ff6fa64b72219e204e4f47e919757a5b1214a5e7682a44da1n/a 
2023-05-17Itjjes.jsjs f3ffd33e93926c3a91670bc83181a9b923d8d971e39e4372e81cf4418e66a2a7n/a Quakbot
2023-05-17Sadu.jsjs 55589a8aedde37454c5c03a3d1301ad6e830d9926ed6478833d29c674d38b153n/a Quakbot
2023-05-17Mdke.jsjs 548d96aa4a3c7c2929462f472674aea80fc26d6a804a5d38b72f89e58b9aac5bn/a Quakbot
2023-05-17Xuki.jsjs d5bd63938b2620ad1b90d1ac0e0a8893c37317ade7f19e5c3ea7b6ead6d38fcen/a Quakbot
2023-05-17Nitqlx.jsjs 316a6fdb40acbf967eed84e29bbde93191d6febf2b75aab3dacbec1e60cc0a7fn/a Quakbot
2023-05-17Mggux.jsjs 268cc62c21c5ec4ac5eb24daa8837fb91709ccc9ca2ef76be3fda3dbf1c91986n/a Quakbot
2023-05-16Tlqoh.jsjs 74779278578ffda339158f0aa1a0611f75ac8855c85a93470888578773c96277n/a 
2023-05-16Mhumhlih.jsjs 1152b15bc10022d4a832c22a15a1c600659eb31ce70398a562b75bc55cd80c3cn/a Quakbot
2023-05-16Knpwkx.jsjs 8dec0dc15cca61dd1fe849b22eabd3daa91711fcf6f6188037ee5a8b7214612dn/a Quakbot
2023-05-16Ujnrrp.jsjs 684ad43ae28fe165a67773c46d12fc15f70e17af7d8e0f7b1c13150a9448dcbfn/a 
2023-05-16Bgtdhozw.jsjs ea0c064b2bdc549b72d6539020fe85f3245687aa4aaaa58e6cbbd7386fe49d8en/a Quakbot
2023-05-16Uuilajd.jsjs 70b8e5b3601a2db323d9894a0c77a9af1cd5df9b10b0420a69a256dfc73a8b6en/a Quakbot
2023-05-16Pmguudd.jsjs 9809590c717fb77bc216bf01f74dd92f0aaeec71f74adfd4e86b305ecde37963n/a Quakbot
2023-05-16Iwgqcse.jsjs 8500662e30bc863f874cb5ff24687c4b0ca936cbc11f8672b887d3e99442b1f9n/a Quakbot