URLhaus Database

You are currently viewing the URLhaus database entry for https://salmanpoultry.com/nits/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634073
URL: https://salmanpoultry.com/nits/?1
URL Status:Offline
Host: salmanpoultry.com
Date added:2023-05-16 13:15:14 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:19:02 UTC to sales{at}dfw-datacenter[dot]com)
Takedown time:2 days, 9 hours, 13 minutes Poor (down since 2023-05-18 22:32:37 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Aglv.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Fcafxvt.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fn/a 
2023-05-18Zjivggny.jsjs 26a9ccdd2cb5bd68aea8b06532a4945f8f6585f5ee8e03fd64c7dd7ba9bde535Virustotal results 25.86% Quakbot
2023-05-18Clkcng.jsjs cb296a47f490cbc70541030b87a0b2d9eb6c1253da849e9e37e7912f2fff796dVirustotal results 35.59% 
2023-05-18Juvctct.jsjs 112fb3f4fda57d58405f842081f111d4f583c40ece7f17fd6805832360da7072Virustotal results 28.07% Quakbot
2023-05-18Niloz.jsjs 0d83b17da8e3318b0fe3004f0ee17572790abab90c15278d5d57ac951953fe5an/a Quakbot
2023-05-18Gzsk.jsjs c7164e6f2a5f4d34a5877e5de94ba49af13d9b6e10be7158adc9e0d267084c28n/a Quakbot
2023-05-18Xzyujtpj.jsjs f3cf1988e5b288b64fc34cf15045d67a4fcd2c9c61549510e3df907ea1f61cf8Virustotal results 27.12% Quakbot
2023-05-18Eefslfsa.jsjs bb62ccf9fa803df4844b790350de975a1f8ea136f9334e3563a5e8ecf4d9b601Virustotal results 25.42% 
2023-05-18Lgwfvcip.jsjs d1a92330c8f58a18b81d7ff1a9ea348b205fda7b106c31a2d1e09764a4557fa0n/a Quakbot
2023-05-17Vvhzebo.jsjs 99ad6e2718d4fa53c8b3e7479802548afcde5a374d0563ab49ffb0405d8e435an/a Quakbot
2023-05-17Brbs.jsjs 5e2610a338e8ef5c3c882966366fdd36d988d79233ad84071b96fe04a7ea18cbVirustotal results 30.51% Quakbot
2023-05-17Gqmp.jsjs 6d790992a3828c5f421e6c85ac319d61de4eb5320ff67d91b8e5d4577865de5cn/a 
2023-05-17Suzra.jsjs 75aba79d300dca2a11da16879bf5c0fd15d388a5926381550db24144937b72fan/a Quakbot
2023-05-17Bfjtb.jsjs 4bc76e07bcd4d492a60a7464d0a8d6c204b4744fac7ea6748a6b673c6ff31cc5n/a Quakbot
2023-05-17Apsaom.jsjs 0651c77d8fadac8f6e3798ca1534ef6af11482867d22cfb20df41d868c3cc727n/a 
2023-05-17Bqzfkg.jsjs db756aef0c52e6f31a7cb628eefe67b0cc7d656427dd2d71c87ecce62165b562n/a Quakbot
2023-05-17Orishy.jsjs a6b6f90d526314e110400b8faffe4bf71e58e4cca71efa73b765a1db440b25b4n/a Quakbot
2023-05-17Laqxgu.jsjs 122314c900a6aff605c478ba0467efb1abb39de9cb6e1dc17e19276c9d9cd652n/a Quakbot
2023-05-17Gphwicek.jsjs 0abff94e2bca73dfe7d9f6d72f73707daebfbc9dfce72648f403b886a96aac6an/a Quakbot
2023-05-17Jccgqbu.jsjs 4aa007a9deecaf59fa4bfe2824fd34a52e6043e4628af3fe3e0ea4b36027be16n/a Quakbot
2023-05-17Qpjxhwa.jsjs 0d4c7e184a32ce09eb8e212974077634f9c844a6b475d4ea801d6ba0791b0388n/a Quakbot
2023-05-17Jnaipev.jsjs 21f6a6396fad3a0bc99861a2ebc54e921f7efca978a5295dc7bcc140d42209e5n/a Quakbot
2023-05-17Yphdbjd.jsjs cad3eb22971591de873b5f8cf7a392bd9e786486501c1363650de7b3cce308e3n/a Quakbot
2023-05-16Fjltmmlq.jsjs f88f8010013c8f93513721443b0d2732c8bff9738f7ca0546fee41ce3696436fn/a Quakbot
2023-05-16Yvvnc.jsjs 037c0fcbc6b79e04176fdfec10bed98657ac410b88fe7de40c6b44695eeaff53n/a Quakbot
2023-05-16Rvzc.jsjs 71cbd5426bc3236a322d0a5c83efb1e9638067d50e988c408e3364ebc06a0e66n/a Quakbot
2023-05-16Eaowoz.jsjs d3d21a3c5821e0585e6ccddb3486f0edec2ba21dbdc8cf9de96e24c792b2e553n/a Quakbot
2023-05-16Qosbte.jsjs 2bb36c8cc2e49784ae765440b1f5211b4b105e052de7ecc699f0c0dd7a17059cn/a Quakbot
2023-05-16Hbsyfty.jsjs 09db9ded6c6a7a1358c58686feb820292468d8e2c2fb3750e6aa172f18d753f7n/a Quakbot
2023-05-16Vhltrk.jsjs cf2c059b47800457f68c69cdb8ff26ab138df7de821a288162aff10446577e60n/a 
2023-05-16Cbpz.jsjs c23df0607974e2c3a4248b777f94e4d61b0b461742fc8cff5d1971a77a902484n/a Quakbot