URLhaus Database

You are currently viewing the URLhaus database entry for https://kreyf.com/reri/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634133
URL: https://kreyf.com/reri/?1
URL Status:Offline
Host: kreyf.com
Date added:2023-05-16 13:42:07 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:43:31 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 8 hours, 59 minutes Poor (down since 2023-05-18 22:43:01 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Sjbkrnp.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Qrmbjt.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Junflmq.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Luwa.jsjs c407227fed53843f6e79437c6c8034600d676ad7041a3552c035983b7a04db13n/a 
2023-05-18Xunfq.jsjs 8fe6b80c39f345411e663560d164edb44cbf0ad7ba4914ba79f02bb403348f27n/a Quakbot
2023-05-18Znetec.jsjs 6637cd86cb6d1780d474d49c347f8accc08a24f73ec7d212ecaa591e370d7e1dn/a 
2023-05-18Rhalr.jsjs 42b8297467af3118af88bc8bd71bc4b1cff09e2fdd17dd631cda319c5c4cf592Virustotal results 24.14% Quakbot
2023-05-18Vnyotmze.jsjs 80f6fd82b28ccaacb151e0447865a17ab4711eefd8ab38eb96bff981a7077a9eVirustotal results 28.81% 
2023-05-18Todibq.jsjs f51bc0d7dd86e4e6db698538eca1063e4e4936ee3f57c669e347f143576749d9Virustotal results 30.51% Quakbot
2023-05-18Wfqeievj.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-18Yuop.jsjs 1d57c903d9a9f7a6aafe34d3d44ced534b1878b64b93029c391c25c05c708094Virustotal results 24.14% Quakbot
2023-05-18Pibchk.jsjs 3ac894a6a388d20bc81ae5f8474ee788079f5036842b1542150a55c8fed2059en/a 
2023-05-18Vmwgijkv.jsjs 307a3ef8bc1930af1d46fc60bac9820950e278feee14f7a931ac745613568698Virustotal results 23.73% Quakbot
2023-05-17Jhwczjdz.jsjs 5382511d86a2d24fb5f8fcb921bbfd21b64b9c071494bcfd096e738c2464ebdfVirustotal results 26.32% Quakbot
2023-05-17Glry.jsjs f4fb9e206467712813d87a31c0ea3285bf1a5ad9658839ca77ac0a61dcbf0693n/a Quakbot
2023-05-17Xlms.jsjs 494e69eca209ceb575b3ad74ff164605bc99c57a7621108280f95412b64e0becn/a Quakbot
2023-05-17Wxfh.jsjs f37d3c915b896922eed07327ecc8b944fcab1445d20c02c26c5aab8d91473b45n/aQuakbot
2023-05-17Ygsxgj.jsjs 3cc62e68f657fa870eabb640cd8e651d4ee69a242db9feadeecdbe6a0435ea99n/a Quakbot
2023-05-17Rdpsjoqy.jsjs 1c70b83f5b4051ac542278897c3b02f334291507f01f685e95893c574241e6b2n/a Quakbot
2023-05-17Ffuk.jsjs 9fc93269f064d50db15333e3dbcf15dccb35094dc51bedfc465ba99ce6a37953n/a Quakbot
2023-05-17Qnmtpa.jsjs 38601be2e7a80c0f3b2f2f140d8d918450cbace4f650fe4fed10c96fccb0bdean/a 
2023-05-17Zxxfm.jsjs 048ea0a514550cd913eeafef89e2af40d1ff7e4c3d68bfce8a06b78b8c91dd17n/a 
2023-05-17Kcjbmrx.jsjs 6c8cb80047c074ee3e84025b480e8659a76018359fe5a9d4662493a50fd7eaebn/a Quakbot
2023-05-17Ccmruse.jsjs 2e649a4064d3244b2f05e562b32c52e2c71028a1d08c2562b00fc73cca01546cn/a 
2023-05-17Dajj.jsjs ba2d7d837be2157c770d52359050aab7720af868629b1606a34e924b55a5a4c9n/a Quakbot
2023-05-17Vxuvk.jsjs 423755205d7a01d57c9a24039297ecaa9b23c8800a5db012ce06d3fcaf2e7243n/a Quakbot
2023-05-17Mclkyjyr.jsjs 0b186d420215e41e85c46a445b2efb9817a43ebeaa4a098a17206aed6cb8179cn/a Quakbot
2023-05-16Muexh.jsjs 4d303013c0472c3fae2ed5e5e946f65a8a326f953879d304476ce88cd2373203n/a Quakbot
2023-05-16Bgpu.jsjs 5b6b085330dca7a3496c8f838bcd6ff10e3bc44c165568e2c9aa0a9066654aeen/a Quakbot
2023-05-16Iiapruf.jsjs ba0fde5551f98751b912e596d1174b80456829d349cfa973974aec32b1e4267fn/a Quakbot
2023-05-16Rjhs.jsjs 1902b7fdcfbe1350f4479259f837c65c21e822dde2dfe6eb7c435472abcf523dn/a Quakbot
2023-05-16Ivsl.jsjs 8fd5263e0e9c6269181313e31ebc64bbfddbe9964953e1582fa732cdaf442fc9n/a Quakbot
2023-05-16Ztxyxypx.jsjs 2608cba1b1e6983a09b52e59ff34aca98ba37095c53435719b98a02e67db18a4n/a 
2023-05-16Otrzrjg.jsjs 91bfd3a316b51a076defbe5e5de649e4ea874979bdcfc35fb0a943faf4dff958n/a Quakbot