URLhaus Database

You are currently viewing the URLhaus database entry for https://wilmsimaging.net/uaqm/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634046
URL: https://wilmsimaging.net/uaqm/?1
URL Status:Offline
Host: wilmsimaging.net
Date added:2023-05-16 13:15:05 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:37 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 7 hours, 46 minutes Poor (down since 2023-05-18 21:05:22 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Oxzrnstm.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Hpyr.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Zffripyc.jsjs eecb4b86969d63577c2b5dfb89f2710b6efda2a8ec80f54eb8ff607c9b4a96ben/a 
2023-05-18Mwbxosus.jsjs 71399d25c8497d7f81c87b8f5ec8d5071d8a62ac85ee254638bf8d24feccc5adn/a Quakbot
2023-05-18Qlwger.jsjs bf6a2013ee6092e2d291a06d2f69e617b318a1e842a0d559b91fa1b8f8ea1a1dVirustotal results 25.42% Quakbot
2023-05-18Zhozihz.jsjs c56be3ec9c7d01ede485ea9edabc332ef3aa01f6ab679c4eb6231e1db79db675Virustotal results 23.73% Quakbot
2023-05-18Xjhiqpe.jsjs b4a90889250c70642150c7b822ece35979290cb3664a5f778ccb8195b4c440ecVirustotal results 25.42% Quakbot
2023-05-18Bnlqsrli.jsjs eecafdba553631375cb34761f4cf33cae100547238141bd641f76c3cb87700f7Virustotal results 28.81% 
2023-05-18Vchvxtu.jsjs 03652beb5abeb2e27fe43d5ddbecd035cbcb347a4e522a06b97f53e9c8f2c3a3Virustotal results 30.51% Quakbot
2023-05-18Svnhh.jsjs abab065bf35d31ff71f44feed5659074ee381a93862817826b7b884996333700Virustotal results 25.86% Quakbot
2023-05-18Mshpgbp.jsjs 5284d5807da5986ffb17fdd9761066974cb34030eb5067e7f9a65e48b32f37e8n/a GuLoader
2023-05-18Yisni.jsjs 53b3144d6c4d4163d5317d32d6bfcc11069a721edc167234c3599a6e2aae5274Virustotal results 25.42% Quakbot
2023-05-17Uwjcgp.jsjs 60483947f59c4a843833ac5302fae111fb318dafe639770153154f7e01c2afa9n/a 
2023-05-17Dbrpi.jsjs 6c9b5539e5f1f1b4e1d609c95278f2b4bd4386f4efc315a332648f1467d2b94aVirustotal results 23.73% Quakbot
2023-05-17Anhkpx.jsjs 5058b0ab18a174398413798e655e1f00408418493c371ea109decdfcde2e1608Virustotal results 32.20% Quakbot
2023-05-17Miqsaezq.jsjs ee8f7825f5b87fbdb90f5bc8eff0cfadc358c64cfca2dcb37acfd398d5b2f201Virustotal results 26.00% Quakbot
2023-05-17Xlwu.jsjs b1580417444140f2311d1f0098c4af6163f27ee7fc99281c6c6904870fdd88e3n/a Quakbot
2023-05-17Hkfihum.jsjs 5e30b39e34b262f145f195328ba0967ae018af26240225770cb9bbac24dc377cn/a Quakbot
2023-05-17Jfylbi.jsjs 68f73fa35cc8f6df9d84c782adc127c0af8e5c03ac541bbbee241e8edfdf685fn/a Quakbot
2023-05-17Qqfmli.jsjs 15605da2602a083e46bd02a72a19a928573b781eed5961ba344bcec88f4b5340n/a Quakbot
2023-05-17Tlvokglu.jsjs 87d5ee29df25642f58dfeeba487fd34e423634bc90af7d899f58b1a7e866a794n/a Quakbot
2023-05-17Eukvd.jsjs 2c30544ada1912d49ef8d72746154f71741956beb57be58e10564db9e6e194f2n/a Quakbot
2023-05-17Jcglcbwa.jsjs f26cc515acb5a87c2aa0c1a1a67d5820b08178895bcdcad11259713dea41515an/a Quakbot
2023-05-17Ppbuvflo.jsjs a195657a01c767ecae7b6cefb1b8a6865ec5671234224dbedb9ef408504362e0n/a Quakbot
2023-05-17Xjlgo.jsjs 289fe3ce2b06f72e9dd8004fdcb60131edf04622859eab8b20da67cbbebc8436n/a Quakbot
2023-05-16Zzpt.jsjs 11ad08707aaefde37210eac466220c4e12eeec776c22c60b674b9a8bdeaed4c5n/a Quakbot
2023-05-16Yulkeym.jsjs 25ebe8a12e6e82844dbfba87bb236c352e0ec2a136fd248a6f445f7197ce1cc0n/a Quakbot
2023-05-16Zourhukx.jsjs 5e2839b5c64a88e6bc859d8f1cd81d0103ab169f57d14183e5e21b14b5c952efn/a Quakbot
2023-05-16Aobign.jsjs a105e72e1bff612889cfaf2c20d3563f061e90c9f770ba699c302c69ce060bb3n/a Quakbot
2023-05-16Hqcqjo.jsjs af0ec0cb4de06d3d71f90092d63b8a2b6f2049910b094534c983f55339159bc5n/a Quakbot
2023-05-16Nrtnopml.jsjs 8b73a0c05237d18508eb1e804475a378a43df2b10c02f1d2aaa6af76fb2c800dn/a Quakbot
2023-05-16Bcjik.jsjs 760fdd6d8e2cbfaf0659fd7ea97fdeb9fd926facdbb77a716958ee4a9af8432en/a Quakbot
2023-05-16Wabtqouj.jsjs fcf97f1f6fa5a2b7f0623f2ffd33602371d45731914eae829717d6572da35e07n/a Quakbot