URLhaus Database

You are currently viewing the URLhaus database entry for https://activeconsultancycorp.com/tpa/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634058
URL: https://activeconsultancycorp.com/tpa/?1
URL Status:Offline
Host: activeconsultancycorp.com
Date added:2023-05-16 13:15:08 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:47 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 8 hours, 48 minutes Poor (down since 2023-05-18 22:06:55 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Kdexwcoh.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Vlfinelg.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Ublqqf.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Wdwoc.jsjs 9f97fa83d1d1aa36e3c73f48b4dfc209cb008f023bb442f75d21aca46ebca2e7n/a 
2023-05-18Kfohs.jsjs e000b46c0d6abfd08c10602eb092657cdf4c49e578302729b7d31ae55a978a5bVirustotal results 18.64% 
2023-05-18Hioxbvk.jsjs 4bc76e07bcd4d492a60a7464d0a8d6c204b4744fac7ea6748a6b673c6ff31cc5n/a Quakbot
2023-05-18Ycprb.jsjs f064ddce080fc01f0b5b378227f89a1ee2f48034efc22bcdba315de07adb217eVirustotal results 28.33% Quakbot
2023-05-18Ynhw.jsjs 134b8da7c15c769cdda57799cf4c8b3e35b0937c9709e7c8e13783183ec10341n/a Quakbot
2023-05-18Uentdl.jsjs 043c810fd7d77672928841fc44891531ce536c6b4cfb9a4e54529c20b36eecd2Virustotal results 30.51% 
2023-05-18Cctxvvht.jsjs ad227c276250c72ebaf4c13e5d960347009d0762b8c2e696a35b36232e0eeff0Virustotal results 27.12% Quakbot
2023-05-18Yxtdcpi.jsjs 1187259a79f3d0fa43b025751bffb4506d955db2a1072f8e61e3707c5250edadn/a 
2023-05-18Poywn.jsjs f0ba5660e9ba7e62c93207a7b6fd775ee56ae1fa8dfc2ece0f169a6e96076681Virustotal results 25.00% Quakbot
2023-05-17Djlfijbr.jsjs 72b50fe52615ed2facfe5a1517ed75f7ba6d2d98e26968645dd646186fa5fef9Virustotal results 24.14% Quakbot
2023-05-17Cstiutuz.jsjs f65cfd45df99f110dd5e24acdcb4a032a333c2d5f289d2867feb0d7fc6aa1960n/a Quakbot
2023-05-17Fnyxvg.jsjs 6003ec795de91a5d5a9a9abb15e037b5f4dcd8cbf43bac5330005fdda61c603aVirustotal results 25.86% Quakbot
2023-05-17Qfvc.jsjs c56be3ec9c7d01ede485ea9edabc332ef3aa01f6ab679c4eb6231e1db79db675n/a Quakbot
2023-05-17Ixvtrnh.jsjs fcdd7c512aa91e5f6574a7c7ab77a118b9e1af5f2e3b502a5adb136508c4ba47n/a Quakbot
2023-05-17Dpgyvbds.jsjs 78416fcca7554fb3cc440610418511210e0dc5abcebf75ace7c1ef65d4d29216Virustotal results 25.42% Quakbot
2023-05-17Wauea.jsjs 85341f4b78166b2b1fe18125caf6a187b8c29c45ce7ef3956530cfd4bd6591e0n/a Quakbot
2023-05-17Mwjexgzp.jsjs 654d79d5b714216fcec5efd06082250b58afb76155c0be229ba139acd68d0797n/a 
2023-05-17Uxepi.jsjs a958cb6ff5873e7fdb3c6ff24ebc4bf34df43fd1fe89b4fb2aff9dde2f1e6d54n/a Quakbot
2023-05-17Rkvpg.jsjs 96ab0326fbaef1b4ebfc2ed02840121bddb9c00ce2693e1bff7a442e38ecab48n/a Quakbot
2023-05-17Wwavfzs.jsjs d08c0e29dfcc49be20f1a9bb646939eb6353f3e7855dfb47b557b0fabb0fbe7an/a Quakbot
2023-05-17Zsop.jsjs 24ef9f42a7dcc5661075a09f407d577352d69e7001dc2516f3088995cfe0c298n/a Quakbot
2023-05-17Ptrtagl.jsjs 008f850fd973e6a970b21ed7339fa0f27c914eb964c863690391208d87d87a87n/a Quakbot
2023-05-17Dfhp.jsjs 4d104e58d35c387010623e8cb854ac32b62657de0ea413c9f40b162eab6b7431n/a Quakbot
2023-05-17Rbxvxpz.jsjs a8285aeed48fa703227e2fd93e4cb3d292817851be52f53f43c31eabeb0a1925n/a Quakbot
2023-05-17Ysismimq.jsjs ca044f3114d0e44f19ee30434935190ff584d1a6f7fcc5c7886aaaeb17a7a9afn/a Quakbot
2023-05-16Rmtmbyq.jsjs 8844b8543c14ecbad1be349586221164790006a30fc1512a51616ddff7471f7bn/a Quakbot
2023-05-16Ocsx.jsjs 670e18d302ddbe53ffdf4d141e54e0d3d459749bf1b2de5a789ed2bfd31d6f64n/a Quakbot
2023-05-16Eowhrl.jsjs d6c29b4705e737aedf386e692f8519b48c7f891f2df019951f32b37253705f2fn/a Quakbot
2023-05-16Xyhbzl.jsjs 310dd5ae96bc151bb51b92988eb6f4504f60e2b4fe92b751cd91fd3b14e3dc55n/a Quakbot
2023-05-16Fshx.jsjs 5662063f0fda2e03c4f44668bd7100d9a81c41ef3a5be1696e46f7e7308af6e0n/a Quakbot
2023-05-16Dayvb.jsjs 01ed35a332b4cf02c37fad87d2769b1ea65810d3cb172e20d7d807bd33cd7b5en/a Quakbot