URLhaus Database

You are currently viewing the URLhaus database entry for https://everythink4you.com/ues/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634030
URL: https://everythink4you.com/ues/?1
URL Status:Offline
Host: everythink4you.com
Date added:2023-05-16 13:14:59 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:22 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 9 hours, 30 minutes Poor (down since 2023-05-18 22:49:06 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Gajazmlp.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Dmsra.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Gkoddnl.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Iapwywxg.jsjs 60b88b0b5aedca060ab867e749d7f8e8789b12ff49a050e7ba28b6914503c72en/a 
2023-05-18Rwexzula.jsjs 719ff669cd7b0754e787346601124ede6c1238c49809ebd0d6b58a3bf4b5a9bcn/a Quakbot
2023-05-18Kmnmz.jsjs 3ff223428a9d2b7b897fd823e4add6ae4cc119c86e47eb073bdbf5a578a17226Virustotal results 20.69% Quakbot
2023-05-18Vhfctc.jsjs 6880ce894904976fa0bcca1c18a48cf2a862737e355802fd26301563e6a09454Virustotal results 27.12% Quakbot
2023-05-18Kqgkpevg.jsjs ff4f21489a82d5367cbd581c4dde86dc238f869b950e07bf20f3928f7e6c7567n/a Quakbot
2023-05-18Aamq.jsjs a6974773e37cbd56791b75effa167213997aeaaa65d704bd1de8aac6d9dd42ceVirustotal results 30.51% Quakbot
2023-05-18Cwoxvhli.jsjs dd49f4bd134e3d669ea1daeb866bffdb27dd69e46b07dfc3b04758e718b40700n/a Quakbot
2023-05-18Sdhcign.jsjs 1539b3e778af6f644e932c0910705fec144fe2bbef2f8df241b0d4bb821d0fc5Virustotal results 29.31% 
2023-05-18Ananl.jsjs 42c81982e5f4b734f8ff57da5bebf9b6d8f79c468dd97a2b69b831657bbc8258Virustotal results 31.03% Quakbot
2023-05-17Kyni.jsjs 35c35c65a46137ab025bfda60be1ea1c10a10b9cae6e337415b9c7b2ebd3df3en/a Quakbot
2023-05-17Eifc.jsjs 2312d94387e675afd3db56f1fd5419a3a083bea7bc690341fa3d49d3e3f69f53Virustotal results 25.86% Quakbot
2023-05-17Vazitl.jsjs 09f9e4d8ef85ba407416a7d168207db81c2000eabea300624e17d81f58bd0b18Virustotal results 31.03% Quakbot
2023-05-17Ksucucb.jsjs 6debfe0d45ae5dd2dc9622ccd7c9480a487bacf847087e1fc8c10ca87a65e7a2Virustotal results 27.59% Quakbot
2023-05-17Ahaw.jsjs 4a5bb0d1af42aabd643a23c518cbc77c4a2931fab8d180bbad1c0ea815f5954an/a Quakbot
2023-05-17Pxhxvx.jsjs ed175d3585ab2d387e6c4a9420d8aa055d62ef6670fbe83a0f66d5bfaf943a92n/a Quakbot
2023-05-17Hebhdz.jsjs 8137776de93065111f5d6fec19d1e8fb07d9e1bb8a3a2705098f54720d71282cn/a Quakbot
2023-05-17Paowcjb.jsjs d88cfa8361a550adce3ead31acc45103b9568e0497e0995eb94b80f55306aac4n/a Quakbot
2023-05-17Kjrabnh.jsjs 7b7f4d434ee0c761429a02a0db2e1f16d193cb3d289838a3863f41e803f4a067n/a Quakbot
2023-05-17Mxcohs.jsjs 1076b3237153edcea2d9b926380237350b79a8e983c62ecfc1a81284267d0f03n/a Quakbot
2023-05-17Nkudxv.jsjs d398ead02fbd10d2adc04d838431c1a97f27d40af525b59170f813f9ce09e3c2n/a Quakbot
2023-05-17Xgktzjl.jsjs 07f7aaced82a897448f5075e20ebf00025b65ebc6e2e90b1160c6ab380b960ecn/a Quakbot
2023-05-17Evzvof.jsjs b8187224484fd7c725ae1b621a3760c6fc45d75cf6e182947400b5f64674bd6cn/a Quakbot
2023-05-17Vsxqim.jsjs d759bca9f3f4ee207986ed1143b0f981688eb27d2be4cf6dc58145a81a2f510en/a Quakbot
2023-05-16Vpxjps.jsjs fb42ac47930a430192e8e6b9fd0989f189d05d4a7fb4ce4866d1861a14b8c1aen/a Quakbot
2023-05-16Qbpfximc.jsjs 9ef0fa6b659c4792fadc8fdb03b80cb505da4bd765799ed8d337c87f33b56c8fn/a Quakbot
2023-05-16Ercc.jsjs a29856b56f8e1c3ba36ed72a2f8dc4ceb546300e78fe2cc3c2c67df53aab44c9n/a Quakbot
2023-05-16Yhig.jsjs 642e207d8e4bf9968a881a7c2203ce96de803fa02a95afa1625352eca6a78045n/a Quakbot
2023-05-16Tjijhhm.jsjs 043ebbb60b8092a19ae887681b462f1ef802b5a7d6bca8866118a463b6f00184n/a Quakbot
2023-05-16Dnqlhi.jsjs 94a3013bf6e5c4e05322a506bbc6d63eb8d3a3f1af0b7a2904ddc35bc9a42486n/a Quakbot
2023-05-16Jghjyaz.jsjs 43da9584ebb9e822cb46e4061f828008f1ec4dce9d0f7dea2c0fdcfc82a36739n/a Quakbot