URLhaus Database

You are currently viewing the URLhaus database entry for https://kenthefreightguy.com/oeuu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634134
URL: https://kenthefreightguy.com/oeuu/?1
URL Status:Offline
Host: kenthefreightguy.com
Date added:2023-05-16 13:42:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:43:32 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 7 hours, 51 minutes Poor (down since 2023-05-18 21:35:30 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xglzttwe.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Kauehma.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Yxjprpo.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcn/a
2023-05-18Pmmwwn.jsjs 8b5a063138d39c424fbf7ce7022dc972afa3c2df792b3a030272c1c77490dc96n/a Quakbot
2023-05-18Fwaxsgz.jsjs 4ade6f7d7cfcd03dbffdfe401ed93fa601500252c858fa6010e54b0587fa0249Virustotal results 27.12% Quakbot
2023-05-18Pwyoojsf.jsjs 614b789451a47511f7b28865dc84ac5a5214ce91e53b5f9ebf50cc64c5cff4d0Virustotal results 25.42% Quakbot
2023-05-18Kkflv.jsjs c28a0689fa744ad9aa6b9113d992a9fc9d303cf30f2b622975fb5e9a82ac02e6Virustotal results 27.12% Quakbot
2023-05-18Phmgt.jsjs 0e3f95cec4063907bf68a435963ea684b5f9bbcbdd4ac6337048ae70087a81fdn/a Quakbot
2023-05-18Ixtwghme.jsjs 269dec903e55df2babe1cb8bb498ac7fe56d2a079cdf89c2d5c354b7a8fa1250n/a Quakbot
2023-05-18Abuqulvy.jsjs c82de2729716408ddf8dadbc7c96d591774e13040bd782c4b2f6f56ee2b039d5Virustotal results 30.51% Quakbot
2023-05-18Ftkebls.jsjs 502aa2d56dbba3e18971b863336aff4b696a67a0935ca0cc3d9186a3c2c8550bVirustotal results 28.57% Quakbot
2023-05-18Rdukljut.jsjs 68e8f2f3d6612aa52ea6f93813be80d9984f0626bfb504047a29018c7e7748a5Virustotal results 27.12% Quakbot
2023-05-17Koospdqv.jsjs c936abc12d461d92641e807274f5df2fb3c02f2e568920845092ed9547299bafVirustotal results 8.47% 
2023-05-17Fwtgmhf.jsjs 4a5bb0d1af42aabd643a23c518cbc77c4a2931fab8d180bbad1c0ea815f5954an/a Quakbot
2023-05-17Xnqpl.jsjs 1e96a7079b653386193018082948ee18ee1ca517dd96395eb46b4d5e30507b87Virustotal results 30.51% Quakbot
2023-05-17Idqduczl.jsjs 91f2349ddffafc85ec07721077d9d38a2ab0376beaf588950fe98bb16d3218efn/a Quakbot
2023-05-17Yjap.jsjs 7fdeda1296a36cffb37a03dca1e25125b27333e53ead2391247d2790dffd0e7aVirustotal results 32.20% Quakbot
2023-05-17Bqmmq.jsjs 92f5060e9693041974047a3d61fa5f29676b1451f9f09d9dcef17ecdde52367dn/a Quakbot
2023-05-17Gisgfvtz.jsjs fb2bca8ce3aa4207fc636e9ebc34bb47cc0d9b6a233352bff3b6875b6bedce3dn/a Quakbot
2023-05-17Empihn.jsjs 119599abab2668cd69abfc97f02c5e1bd50de874150cf6a3eb7bfc2a12df9a30n/a Quakbot
2023-05-17Ukpul.jsjs 71a8aa6d7b6ef3c3ef8cbdd5da25cd13a3ab5e1eb13f14f196c07d42a2d90168n/a Quakbot
2023-05-17Beoq.jsjs 563ff5cb25b08699f2d56d63c9c7d58e3fde72a8b661c830017eb512ae8f2cdbn/a Quakbot
2023-05-17Zwlxt.jsjs 31bf4d5c5fede0178031b0fa2340f3049a23d2b8dc8fb8a5881e6cfceaa4646an/a Quakbot
2023-05-17Dmvyl.jsjs 37f205814b16dc23cecf7ddd526c9e97f55f68221f4f5d2673da3f19c93897e4n/a Quakbot
2023-05-17Ebacykn.jsjs 87292372ddce2d01b2faca1aa50b1cc910ea282cebd539e6c04feb1491a03d82n/a Quakbot
2023-05-17Vybwi.jsjs 08010b64b4e8909fd6e70c87d93961044f073bab22958cb06f09745238118729n/a Quakbot
2023-05-16Lfgeof.jsjs 2008ff2fb2c6b2d581255346f37db7304a669d0c86dac5e086aedfdc42f60b33n/a Quakbot
2023-05-16Cyofj.jsjs 138844fbec57221989a58485773f786ff2e2192973a85a388570acde2170075an/a Quakbot
2023-05-16Rluvl.jsjs 64aac71136ef71f505f6f18744169ec54f8bf6459e62db19b0e413e2ccbc6aebn/a Quakbot
2023-05-16Mppxhsc.jsjs b05dc9e65760a2db32375c740008a36a3a0c623fb8f4e4b7d6e6bd951aed54c2n/a Quakbot
2023-05-16Hngfgpy.jsjs 1ecf6481fcd99e82bba37f4ee8a86df45a1d47f8243e932cbc8f2a7ad6d09d48n/a Quakbot
2023-05-16Wrwm.jsjs baee1fcfda62c36eeed4ce24759c6c812c10c9047e340191500a2bb8d95e7fe1n/a Quakbot
2023-05-16Nuvjusnc.jsjs da200b4e802a442b212f451504ecb20eb84591a4857a94e7e30022247593712cn/a Quakbot