URLhaus Database

You are currently viewing the URLhaus database entry for https://fs-ao.com/rmd/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634061
URL: https://fs-ao.com/rmd/?1
URL Status:Offline
Host: fs-ao.com
Date added:2023-05-16 13:15:09 UTC
Last online:2023-05-16 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:50 UTC to abuse{at}register[dot]it)
Takedown time:2 days, 7 hours, 25 minutes Poor (down since 2023-05-18 20:43:49 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Jxwlfblw.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Osoqxdwi.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Uofk.jsjs 1bff54d9504766a1b23df7d6c83ffbf3db9ac0d0cc9ded739c34a0f1114f5717Virustotal results 27.12% Quakbot
2023-05-18Hagmli.jsjs 176082ec2166a938b76477a4d42d940987b38d787c43628c9e17e75057338dc2Virustotal results 10.17% Quakbot
2023-05-18Yvwthde.jsjs a7a7249194b741b44bab1befd74e783ba57af2f211b597961892dcbe975544c2Virustotal results 30.51% Quakbot
2023-05-18Ryouijo.jsjs ce5efda576bdfd577cb85bba27c1785787f37d30869878530f7249504d45cf69n/a Quakbot
2023-05-18Vsnff.jsjs b65cfc5c1f188f590ab7d7d6a20d1ea638a086a9be61e3442b6ea9388fda3c0cn/a Quakbot
2023-05-17Ratonucj.jsjs 0651c77d8fadac8f6e3798ca1534ef6af11482867d22cfb20df41d868c3cc727n/a 
2023-05-17Hhsmzqbh.jsjs fecdae98fff4b89aadb8c35ded8061bdaa126fc12f3fd482cbcecd53246c1c0an/a Quakbot
2023-05-17Azfbbr.jsjs 71399d25c8497d7f81c87b8f5ec8d5071d8a62ac85ee254638bf8d24feccc5adn/a Quakbot
2023-05-17Hxiltcyf.jsjs 584184d31eaa8b12397a59f5bd11283b8dc1233df44c77ceb47e6fb0b619dac7n/a 
2023-05-17Twakbjel.jsjs a82344f8011c85bdadfca42b04556147e60f0a78338d80aba22f59f6d126a9can/a Quakbot
2023-05-17Ieovfdj.jsjs df7e9ab50639f852243e4f545194262911468ec6a9735c15bc8367ac61d09695n/a Quakbot
2023-05-16Ltli.jsjs eba35c3ec695c33d6d3cf7a2103edcc8c60ba24c7427bc60133a8d53e3f48325n/a 
2023-05-16Pghc.jsjs 4eda0131663303747bc5065efc75630c26c495663e47383c87f663838684a405n/a Quakbot
2023-05-16Txhavxr.jsjs e555869780551ed7b93434e15e750ea9e9a0853ea4639bdb832d8fda10abdc03n/a Quakbot
2023-05-16Tjfqgl.jsjs 16753b29210e047837f71456ecc69ce137457b2d5e6f6c9c398cc6f87e8591dcn/a Quakbot
2023-05-16Czobuzc.jsjs 0a943d33d71268d6c0a8c49971a2e381382a1de145ae94bfc6ea61543578a1c4n/a 
2023-05-16Ulcjhm.jsjs 42a4c774727ec99eb6e0264df3ccb76a855d419c16c7ddc9c4cc486dda82ff2dn/a Quakbot