URLhaus Database

You are currently viewing the URLhaus database entry for https://carloprisco.it/cs/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634056
URL: https://carloprisco.it/cs/?1
URL Status:Offline
Host: carloprisco.it
Date added:2023-05-16 13:15:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:45 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 8 hours, 3 minutes Poor (down since 2023-05-18 21:21:51 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bslo.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Ryrsy.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Xtnk.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Sjzpout.jsjs d33f2d154f201e710ae5a8a3216120a93a810e0ae586aadaa3d82de62f103670n/a 
2023-05-18Pbyog.jsjs 8f5bae7c3310650dc125b9223695f4a40a6d1394f6f6f9dff466a3e53099ba7en/a Quakbot
2023-05-18Szloi.jsjs a0220d487566d1243b11c30ea5d37349418d84e8f6eb6013e0792aa4b11236c6n/a Quakbot
2023-05-18Frhk.jsjs 3f5e5c65bd5814cdaf300e4fff7de23851e1c5fcc764d920ba42761515bc506aVirustotal results 25.42% Quakbot
2023-05-18Heni.jsjs 6003ec795de91a5d5a9a9abb15e037b5f4dcd8cbf43bac5330005fdda61c603aVirustotal results 25.86% Quakbot
2023-05-18Hctbahr.jsjs 576d80e7bad2be3b3f4ddb0ccbe067bceabbc990bb96e11007cc74c2d6ad7bean/a Quakbot
2023-05-18Ewusq.jsjs a5ad0d19dd6ae50f16dc5be1921c43a887aba5ab8dae04acbea417a5cd62d61cVirustotal results 26.32% Quakbot
2023-05-18Emjps.jsjs e82f04f537f593c6f5469d18db6332febdcd169b2dc920ed7619f9edab951f03Virustotal results 29.31% Quakbot
2023-05-18Vaahsd.jsjs d307232640d2944029109ca441be49052d7c8d24590a54096c256c48e4d7da1an/a Quakbot
2023-05-18Ooppfdg.jsjs 12551eef6e57f08df39d1185caa198cce871f9b27d1fb58cd74228fc3a949b99Virustotal results 30.51% Quakbot
2023-05-17Rkhlvo.jsjs 4ec189841fea600476bff49f643d0877dcdc3e3050e54e56abc5a7c492ed00dbn/a Quakbot
2023-05-17Vuwuyzu.jsjs 0692b014bee9b6b1a01cd4fcf3293e88388f98fb01460d6ffd2b3415d5de9779n/a Quakbot
2023-05-17Jrlevfj.jsjs 7100bd0704b52e63e4581b308b07b43d48da5998a03a3ef43b8e78bf0d855d17Virustotal results 25.42% Quakbot
2023-05-17Jemllnf.jsjs 77a97bbae92dc7a7845ded72bd28a849a3c41c2912628816d93ff4b9a27ed45fVirustotal results 32.20% Quakbot
2023-05-17Gcnahp.jsjs 81f0fe1ef9b350d79e5c368c2f73deec42c5a379bfbbe52f88c1c79ee481b5e9Virustotal results 8.62% 
2023-05-17Gpzq.jsjs 81d46bf6cc71d927906bc2a9ae29103ed6a1d3f01599e9736dd016267c874521n/a Quakbot
2023-05-17Rqeudzn.jsjs 655729ffaa1d79b40a1df6017495f362432d5497a1c79b18220fdcc46d21f2aen/a 
2023-05-17Jwyonmx.jsjs eed1f16bbf4b32518da17a00f407bdb37f121e9107bd33e5dd12032a81673090n/a Quakbot
2023-05-17Fabjbipk.jsjs d060541b93ca72bde4e6d7aae23cc0ae4643b8154c5d000248fec999f6b0e006n/a Quakbot
2023-05-17Hgslj.jsjs e14e5ec68d382d3aeab9420ffa3bc55d5e65a77111eea2a63cee392205fee4ebn/a Quakbot
2023-05-17Asst.jsjs d525388e3f9ee2dc5ec0d2ae9df06591dcbbe46e426e7663468c011501c236fan/a 
2023-05-17Hksfl.jsjs 9b431cb6e733be9be8017a221a7254df46705a2af4127fe38769936daa917b0en/a Quakbot
2023-05-17Ffxmpx.jsjs 3ba2c3215fd9798aeb89dd2c725cba74027f2316a3b0c2517a461067247cb451n/a 
2023-05-16Wwwi.jsjs 518bca642975d813901d91afe678adb31d5953d79102654c5b58ae2dc9ea801fn/a Quakbot
2023-05-16Epkvwknc.jsjs ac67409032823edc82c0db1bf5a7e2d713acc80b8ce48f396ea847f35b67e635n/a Quakbot
2023-05-16Ufxziwq.jsjs b1aa6982d57295cf7b85a7b54ad8f819c7d571557d91479e1025665421057dc7n/a 
2023-05-16Dcbibzq.jsjs 486f03c02baebd40565256d5358d888ec0c533d258e698aaa0632790d48c0310n/a 
2023-05-16Gzzpcona.jsjs e5ca733863b8b27abfad0665ab37db9ae824d212a8e39fd406bf061ed492f077n/a 
2023-05-16Epyvjr.jsjs bec38b0738199acf1eb44068cc3f391362b99d5c788109f33da5a30618e89d1bn/a 
2023-05-16Qoofvjsm.jsjs 81411da81ff328f55dca964a0a07870840f1e1438fd2ade58c970ab2ec86a8b8n/a 
2023-05-16Ltmnkv.jsjs ca502bdb92dc85f17ebf6eca9ed521f6e3527b47446443d058e1efc962597cd5n/a Quakbot