URLhaus Database

You are currently viewing the URLhaus database entry for https://annarborbusinesses.com/intu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634062
URL: https://annarborbusinesses.com/intu/?1
URL Status:Offline
Host: annarborbusinesses.com
Date added:2023-05-16 13:15:09 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:51 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 8 hours, 28 minutes Poor (down since 2023-05-18 21:47:41 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Kbllya.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Cluhpjg.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Qpoiiwp.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Ysfjbbrl.jsjs e7a2efc9972ba6122bda84d38644fdff70b270abac909ebf06aea8312a121083n/a 
2023-05-18Uupmf.jsjs ce5efda576bdfd577cb85bba27c1785787f37d30869878530f7249504d45cf69n/a Quakbot
2023-05-18Cnaxujt.jsjs d4048bb4d8d517078d21db74a0238b8f0696dbad0bfb9cecbe0dad5e3a89bb47Virustotal results 30.51% Quakbot
2023-05-18Djrmba.jsjs 4fc44d998f2dd5c9dd8a2b1113af13a124201f3cd8b1f55511976b52294ef5e7Virustotal results 23.73% Quakbot
2023-05-18Kpfwuidq.jsjs 882f433be14420954cf276d10abb6b832e89ab1dc301d2d047538fab217afdabn/a Quakbot
2023-05-18Gzmrg.jsjs 928de378e1b8690de67deab709ed80da406ac542daf31e7c5859f02c0b9a4240n/a Quakbot
2023-05-18Nhahtrro.jsjs 9f58336c0b0f6cde0a91dbee871cad45a315c5413863ef2b29affc9c949ee72dVirustotal results 32.20% Quakbot
2023-05-18Ypckuky.jsjs 6fc84f16bba8f14130cc061d7ab41c424fdccd71398b2bd8c1f4300ffffe8912n/a Quakbot
2023-05-18Ygteu.jsjs 502aa2d56dbba3e18971b863336aff4b696a67a0935ca0cc3d9186a3c2c8550bVirustotal results 28.57% Quakbot
2023-05-18Ecfix.jsjs 50ebb94dd22b6d976b5ec46e2aaa6756dd807058f1a4fe1497d72c4a355b3c2dVirustotal results 25.42% 
2023-05-17Slrc.jsjs 2a38d5dd759f5e13e433429b8fbed42e9b1fa7de9f671bf87d0739862847c16aVirustotal results 26.67%Quakbot
2023-05-17Cuedcoc.jsjs 5cf5a460458dbbeb9dc56a1055cc11cf9105c55fae9b828a1884c3899001033eVirustotal results 22.64% 
2023-05-17Djhtkk.jsjs 5b081d8987954ca182f1f9c83eb5c24851ef6647e29f84c5fde150d826531e53n/a 
2023-05-17Qwmv.jsjs f276da1a81b23b7f647bba9fedb53f4e8df35e0456b09c909184c6c45bcd9d99n/a Quakbot
2023-05-17Prxsi.jsjs eb40b9246889e25a0aa869bfab07adf9622ef027a8ef2ca488d9926b5a39718fVirustotal results 27.12% Quakbot
2023-05-17Wphszbmw.jsjs c426bcba8c0bf1790fa05cb78d763ad67bedd1b1bc3eec6b4902700e097a1a0fn/a Quakbot
2023-05-17Wnwkkswu.jsjs cc3f6d63f84cc1a94c7b2a3942b9e0df2af0f247cf2a81b2ba18f33ce401310dn/a Quakbot
2023-05-17Efimxrpp.jsjs 56db00122938d0ccc3a77c8cda19ab5bd2a49eb4a2b70f7cebe5686af6fe4127n/a Quakbot
2023-05-17Wzkvfxr.jsjs 73bbe4f19f6d2e28c7d50fbd6c5db1f9bf1b435e6d6058127385ff74a8c01c1fn/a Quakbot
2023-05-17Gawzjlz.jsjs f0e4aae8851e1d8f283a69d7cf63d177c2a9ff4a4c1721c8cca02fb4a9666debn/a Quakbot
2023-05-17Valoxvp.jsjs c68cda86e823795e2c9bd2f13f2d50a5cd339fcf70f8b69e321bcc884cc8e723n/a 
2023-05-17Amaqny.jsjs a211370eaac12b76304e5d5ef77a39c5573709e8771151880986578ae4adde3fn/a Quakbot
2023-05-17Tuylmkof.jsjs f2d0a4a56ca41ac4159ef3ebb8799bff8927903efd97ce6c90301cfc1e91b074n/a 
2023-05-17Bhobu.jsjs 46d20a8127cff37115f7ae9c673ad7e0d46b956cc7c54b82ec961ca0a4c7d195n/a 
2023-05-17Bjmz.jsjs 4a9a69d296aa87bcc23e9e8445cd70fe626005a7db51c01ea04447a6b179a2fdn/a Quakbot
2023-05-16Kmihj.jsjs 668468322d1cbb0d0cdc3a361ee3b153d79e1495f057f6b5276a6708949230c2n/a Quakbot
2023-05-16Djdsjwro.jsjs eb3f975d592e6deeea88a42ee8e77d0f5f115b23a415152beaa15add245fd36dn/a 
2023-05-16Tsueizs.jsjs bddf8bea1c804062277398b966204c9c1be541c333617762dccd9e77ec9b73f0n/a Quakbot
2023-05-16Dvobncqi.jsjs 943a30c050daec9626d9d1e005ceadf1fccedd5cb0c14cc58cfea1c5db966d05n/a Quakbot
2023-05-16Ccloqv.jsjs e939786df923a84622ab3d2b60a61aa326ecc410b761fd7779dc10aa9a890844n/a Quakbot
2023-05-16Wozemgoa.jsjs 36eb7f6c1204b33b6ede3936230cd6d4e6cc20fb56e9cb8b138870909c15f7c0n/a Quakbot