URLhaus Database

You are currently viewing the URLhaus database entry for https://policyproserve.com/sta/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634127
URL: https://policyproserve.com/sta/?1
URL Status:Offline
Host: policyproserve.com
Date added:2023-05-16 13:42:06 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:43:24 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 9 hours, 0 minutes Poor (down since 2023-05-18 22:43:55 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ytxvwe.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Lsxuht.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Pmat.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Riyew.jsjs 9580d4483bff9aedc097a1a25bd7682931d206c8aca62c0f9cb24fb7d59d57c4n/a 
2023-05-18Iiltjfe.jsjs b80551abdf45ba18befb113fb4c02517cb49680bde72f8ae92ef07e61857ec89Virustotal results 22.03% 
2023-05-18Zltgrabw.jsjs b3c3f0880fe1ebd5b9f5146a8164da0834ee29a37e5a1cd8e534efe15c786daen/a Quakbot
2023-05-18Abjzslx.jsjs 85341f4b78166b2b1fe18125caf6a187b8c29c45ce7ef3956530cfd4bd6591e0Virustotal results 8.62% Quakbot
2023-05-18Uopyr.jsjs a23cf11c2f986f5d2412a9c98d50dad0b0a02cd2dbbd6fdb1eb47c20cb7dd2bbn/a Quakbot
2023-05-18Oxcbkbk.jsjs 584680760762a6814ff84e38f5de401a9ba356c834f6302e03634c8883180fd4Virustotal results 24.14% 
2023-05-18Ztawyqd.jsjs fc4e17680da39bbf2dfbf388da243c919927a825eca7d8de8a39d74be04968e9Virustotal results 31.03% Quakbot
2023-05-18Soaj.jsjs 71399d25c8497d7f81c87b8f5ec8d5071d8a62ac85ee254638bf8d24feccc5adn/a Quakbot
2023-05-18Yioxd.jsjs 2072042cbdf8458366261756217da566a1b8d6cf4b24541a37d71c44c07c7fdeVirustotal results 24.14% Quakbot
2023-05-18Uufaeue.jsjs 56e958c5170fa27748c823f1145b93644170f72706fd132b2dfeb286ccf1192fVirustotal results 27.59% 
2023-05-17Eyaiim.jsjs 32b63b6f4ee01c7737a32e2bfd61aca2c688fdbd79e9455010a3a5506954ff0aVirustotal results 24.14% 
2023-05-17Dimytg.jsjs c183dc69a6e054260b5800df8cb1bdcf33338ca9f2d92f1b6d2161ca1fa1b850n/a Quakbot
2023-05-17Wdusmorr.jsjs a5f0035e2f6ab21d643775a304ea994d963bc0ad712a5ae1a9ebb1a5298f7adbn/a 
2023-05-17Ijgntf.jsjs 9be436ae8d8612af572358c0394b27e9c751e6f50b2597c2b7ae636e99088255Virustotal results 28.81% 
2023-05-17Khcxlvsy.jsjs 4422126c61949a9848ddc759de968eb699c5364973a271dc9aac631121591d13Virustotal results 27.12% Quakbot
2023-05-17Zktwcft.jsjs 4fc44d998f2dd5c9dd8a2b1113af13a124201f3cd8b1f55511976b52294ef5e7Virustotal results 23.73% Quakbot
2023-05-17Goib.jsjs 3f883b067422272c3b10eea88505351741b599d103f66676cb75912106735cfdn/a 
2023-05-17Ddopdyid.jsjs ab34fd7c682bc90b82d1d9045cbae738e520b84251a7c9372deda6ee85eeedc2n/a Quakbot
2023-05-17Opplscn.jsjs 7fe6812243b606b4b4f7ec61073a081c113b522e64dba93dca33699547d13a60n/a Quakbot
2023-05-17Lccqy.jsjs b156fe3585b47a820232e50126dc64486395951874861bf816e5bda4c72f328an/a Quakbot
2023-05-17Xndw.jsjs 4570784d1b46d6e94cea212343a2ac84f301742473b80cf257192947ef7d2c04n/a Quakbot
2023-05-17Xmoyyane.jsjs 1c073559585ccfd87c459aba0b886c33382b88b29e08c50fe02e8c5f4d45709en/a Quakbot
2023-05-17Fratbnr.jsjs bdbd68711b8dee4c1ef6b52f97d6ac6e51b4ff02ff601bcfdb4685bc2ad64373n/a Quakbot
2023-05-16Ifriklxl.jsjs 21946ee0f6c09339e3f5f403bb18f2389c9650e2592864e3bffa46ab682b0312n/a 
2023-05-16Upxlcyoa.jsjs 26c46a7d5b51444a1011d9a2f8210c318232241d022384087b660ca7e26dd1b8n/a Quakbot
2023-05-16Zbhskuz.jsjs e952c214c24c061d25301a7701ca5ee7ac76349de2dd6d1fc69150ec052a6313n/a 
2023-05-16Hvfccjy.jsjs 09ec0857885cefa58b80b25b0e4cb9e3f8f146b6976bc18fb72ca18f6ed961c1n/a 
2023-05-16Gqcujx.jsjs fe15c1caa1bc2499c1254ae91bfa804e7b94448920a711bc3b05094cd8cd8f81n/a Quakbot
2023-05-16Cqtjhvg.jsjs b3795b26e51f29270e8a75df03584f6a94efdf03e3eed316c75b1ed8b9fb1477n/a Quakbot
2023-05-16Upemqluz.jsjs f3b03e5328b5786c53697a5150165dd1b8a487c67be1f7e7293e602cb992aab1n/a Quakbot
2023-05-16Ilcatka.jsjs 0a409cd3c44afa99371953c4a1bb7d90db36fa97f3638270520ef3c09059666an/a Quakbot