URLhaus Database

You are currently viewing the URLhaus database entry for https://everpayawards.com/eu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634067
URL: https://everpayawards.com/eu/?1
URL Status:Offline
Host: everpayawards.com
Date added:2023-05-16 13:15:11 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:56 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 9 hours, 34 minutes Poor (down since 2023-05-18 22:53:35 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Oudr.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Rnpap.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Yedna.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Vczuhikz.jsjs f364589d1ceb0991911e6bea22a0ae624ba2e77c9af35e1f232461748d65556fn/a 
2023-05-18Ddxprz.jsjs 36fa7b7d4e7fc7c9366c2fa6533c47fd96cdc2d9a6f2c3a9025fc4271c5d4c18Virustotal results 24.14% Quakbot
2023-05-18Xstanb.jsjs ee8f7825f5b87fbdb90f5bc8eff0cfadc358c64cfca2dcb37acfd398d5b2f201Virustotal results 26.00% Quakbot
2023-05-18Vzee.jsjs 9162c26ac66cb673664c91b6a22e788a008db7c2bd2b4a9b7788a47fe85f33eeVirustotal results 28.57% Quakbot
2023-05-18Xglcn.jsjs 4657c8d962a15da8cdc6ff3c1ab3d492a89eebdd09249e8d29eea382791500abVirustotal results 28.00% Quakbot
2023-05-18Pibqstxp.jsjs 81d46bf6cc71d927906bc2a9ae29103ed6a1d3f01599e9736dd016267c874521Virustotal results 11.86% Quakbot
2023-05-18Kzsv.jsjs 6880ce894904976fa0bcca1c18a48cf2a862737e355802fd26301563e6a09454Virustotal results 27.12% Quakbot
2023-05-18Gdxqywk.jsjs 2d4fa148f948ad83cb6ea9d45930d0384b699b8dad0de5e48214d4fcd895cad5Virustotal results 28.81% Quakbot
2023-05-18Kaxul.jsjs 7de33bd597e2308019574ea948f706768bf2fbb89ea7392395d6cfd89909369dVirustotal results 25.86% Quakbot
2023-05-18Socomint.jsjs 86cf4c93687b588dae11523a8db9355990fe06f4481aa096e4acfcd8555b8e25n/a Quakbot
2023-05-17Ovzn.jsjs 3769ece7cf8318e31632260f0a962a6c155adc7adcb91cb53a6d50100a8f3281n/a Quakbot
2023-05-17Uyitl.jsjs 928de378e1b8690de67deab709ed80da406ac542daf31e7c5859f02c0b9a4240n/a Quakbot
2023-05-17Fcufwcg.jsjs 20bd75aa446aa0b87c0d7042cd6119cf26dee2dedc5fe401477ada73a6c84e1eVirustotal results 22.81% Quakbot
2023-05-17Jfrmeqd.jsjs b19665dd5f7dbec102ef5c751b9f86dbe37003d54eb666e3be898351373a0486n/a Quakbot
2023-05-17Hyiholqm.jsjs 0d19b7d7e092df5355727bab9cbf454b5b17f90d5380ef6240d0cada7cb5a1c0Virustotal results 15.25% Quakbot
2023-05-17Aptpgcoh.jsjs d25526dc27feb5e67f938d4b403a9dad1250e9bad80e8f4d66a22d696dacc328Virustotal results 32.20% 
2023-05-17Vvcs.jsjs 7e14e82b93e7a51daf3ab028772a41e20e60a31cc1a90985cf3598206b08805cn/a 
2023-05-17Imln.jsjs f14437be247480b6af38f3ccdd4ba46e6e55eb7b3d706b8df711f63558b8703fn/a 
2023-05-17Sukh.jsjs 0a1a899131d5f969556f19fd2589ae607d2c688b72eb8cecdaf9669d7239b454n/a Quakbot
2023-05-17Dfsxup.jsjs acfdbd568710144ae0f312b2e332d9482497e59ea6d9dc14afbf77be16deb1dcn/a Quakbot
2023-05-17Bxbxg.jsjs 9e94c76ede182dbb8714ade22856730729d8d78ee7dd8b5f06d8ed44f0a8dacbn/a Quakbot
2023-05-17Tiexygvs.jsjs e210a2b1a2c9160a7eb050c9c775b6dd8260818161cd019861c4e17b08307bcfn/a Quakbot
2023-05-17Syxpopl.jsjs 0bc603216626a5ed8b9ace1230b8d62a21e611bb4fe1d6e6bec9b6fdc6205e14n/a Quakbot
2023-05-17Bfvlufrm.jsjs fd3d5f1737b600665783285c8a44fc9ba5da89649a2e0ac4565e5536f3373a37n/a Quakbot
2023-05-16Bizwbefj.jsjs f56bdc36587390463c27a0e4306517aa4722e57b42d20e3e50db6f9f012789bdn/a 
2023-05-16Zmqdkc.jsjs 1e65b0117c5ab7da4b8ca56b6a3046a71a2b9f705b33c7d8ff9eacef065eb222n/a Quakbot
2023-05-16Oftsg.jsjs dd68f66a96de7ea7ddae20fb69afff2f08f82fef5807d49dc4b7af665b3b5759n/a 
2023-05-16Yvfgsftr.jsjs 969f5f3d4b22a7700e700d7f2627f9b9334af9536c215334c2ee83a087877710n/a Quakbot
2023-05-16Ycxpwol.jsjs b811e0967da75200e4771280e4d1b577ea2c8b425670704a30b223fca7cf8d0fn/a Quakbot
2023-05-16Gttj.jsjs 88665a4a77090ace248b0d10834f239b5fa436b6f4c0a0629c464c6b2fee2905n/a Quakbot
2023-05-16Hjosl.jsjs 2f45469b189038cd134164f6ec598fd2337a95f0632121f4bcbf307ca5b4bd64n/a Quakbot