URLhaus Database

You are currently viewing the URLhaus database entry for https://visualmed.org/us/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634070
URL: https://visualmed.org/us/?1
URL Status:Offline
Host: visualmed.org
Date added:2023-05-16 13:15:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:58 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 8 hours, 16 minutes Poor (down since 2023-05-18 21:35:00 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Mktyn.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Mlzlmt.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Vibim.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Dwjh.jsjs 87e213a738e533bf5a0f82cad663f9b83683392740d571efb40529fce5322ca8n/a 
2023-05-18Sxjemcn.jsjs 2c6c3f6ffb898b9a29cc0a5ec84ccecf30800496946b378d5558f81798278c3aVirustotal results 32.20% Quakbot
2023-05-18Aczq.jsjs f39cee789a4050e31f3f61e2dae48c0b5328d480424a439ba3c06fdf7d12ba43Virustotal results 29.31% 
2023-05-18Kaqkvraj.jsjs 95f993cc876a8c3aa072647ab634b4ef2df037d739e781cb6f6b4e90ae5d6889Virustotal results 25.86% Quakbot
2023-05-18Ssre.jsjs 7f5bfd748f09cddad1977aabe48a77b4aa3281b4bc9ac685ca0e53226b92c107n/a Quakbot
2023-05-18Ksvhryks.jsjs bc100a785f531874618920cd99c357dfc32c33cd59fc6b19856a94b41ca3f07fVirustotal results 30.19% 
2023-05-18Orto.jsjs 89ddd75a9d671f30070d8ed74468e507a72e5ca5699855296beb959dae2b71b3Virustotal results 11.86% Quakbot
2023-05-18Krrk.jsjs 3657123d41437d5c2c4b48b03e14153b367398907ae10d30021c974941a5b64cVirustotal results 32.20% Quakbot
2023-05-18Cohmm.jsjs 0e8413c3fd2b87cd2139ba54c718d6b9f305a8bf33d41f05aaaa2639ccde842cn/a Quakbot
2023-05-18Bopewkz.jsjs 176082ec2166a938b76477a4d42d940987b38d787c43628c9e17e75057338dc2Virustotal results 10.17% Quakbot
2023-05-17Kjnjp.jsjs 5089e9979f6a45bba9ac940e1e725185230875623b2242cad8dfcf968141f073n/a Quakbot
2023-05-17Miinlgq.jsjs b4bbe3eb6f77c745b1c296728e15c69c6b766df2aa51d6d745ce4e5fee415e06n/a 
2023-05-17Jovhw.jsjs 456c54257858cdc9347b6b71444659a256ae3a000dc1c82298d0fc65ba890687n/a Quakbot
2023-05-17Mwxterf.jsjs 9487aeedb7473998494f4a53f02cd176e21f14043b6e2e75cff9016c277d0c0en/a Quakbot
2023-05-17Toguj.jsjs cf3f8bcfc47120345a6bf7e2b44265e2cb07dfc6d6aae1290d5552e5f6d2e1f7n/a Quakbot
2023-05-17Pucn.jsjs 185a635c927d918ae74aea58092eb9ecedc06bed0129605f9c210f1a3ad2d63dn/a Quakbot
2023-05-17Hrxbae.jsjs 91fc2f32f2c947bf268461f957fba24de171292fe13a0f4430f87f9d6ca745b6n/a Quakbot
2023-05-17Dssbc.jsjs 895a7d4baf83b1032bb28356cb7cd178316a4fb2f992ad74e757ee0d21581517n/a Quakbot
2023-05-17Aouz.jsjs ecffd9448b2b505375a8b9cf0663a4d114e9bcb8c96654abf0dd03f45f238984n/a Quakbot
2023-05-17Jpmqrers.jsjs 0c0acbba3858e8e372e6e25ddf0b38542fb1ac65def79d3bb62b32ab937c0806n/a Quakbot
2023-05-17Pwoz.jsjs 7fb84dac1170501dc89ecf4da63210fda6467f8f96e12f64730a1b6c1053b35fn/a 
2023-05-17Pbspefn.jsjs bd3350c17755a35f268b74a0d931607685e46c4ca8a29103eacf6a46e8ea99d8n/a 
2023-05-17Londoz.jsjs cb6e9cdb4243a93693306fab7350552080a6bb2b0ed3ab34ff01f611243ca65fn/a Quakbot
2023-05-16Dfmtngl.jsjs dd11dbbbdb87cce7c6cdba9a2512759778c4c167d6da2c469ebb049966ea5fc2n/a Quakbot
2023-05-16Jegsetvt.jsjs fb4992b9274c71630a14e19793124b91637aca42e9393e0e8768cfe648d75fb8n/a Quakbot
2023-05-16Alxekim.jsjs ee6a0910acae3ae80e50b9cd6db228fb33a46d31721e4c7157cb973b86d7a979n/a 
2023-05-16Galffz.jsjs 2550f6d8b7ec43a0caf3004881df2bd2eab4e4e793b083fda6345d7ac2eb0689n/a 
2023-05-16Wofsup.jsjs 206dfcd7021177474b37c7511e3178c7587ebddbf6fce71bb3542994edb20a2an/a Quakbot
2023-05-16Fzoffiq.jsjs 59b85638d115e423feb69ad6c3bed67f253ff07674a09f3b10e1d95c1a5d1e62n/a 
2023-05-16Zvbxg.jsjs abb42ffb84ba129280fd739e7a57ba14d2971bbb6d4e35cfa139cfab728a764an/a Quakbot