URLhaus Database

You are currently viewing the URLhaus database entry for https://maraboutguirassy.com/tia/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634141
URL: https://maraboutguirassy.com/tia/?1
URL Status:Offline
Host: maraboutguirassy.com
Date added:2023-05-16 13:42:08 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:43:40 UTC to abuse{at}ifastnet[dot]com)
Takedown time:2 days, 7 hours, 38 minutes Poor (down since 2023-05-18 21:21:51 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uwaxcf.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Jtsb.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ezzojxbx.jsjs 7de0664cebacfd1e6f4d0d5c0ac89a0c7f395dd87da6f57eb69fecd8bc265610n/a 
2023-05-18Hktp.jsjs 743cf712f367f3c69cc6bfc3a3734a66d19bef6e76aabcc6a8b97c534a3b5557Virustotal results 30.51% Quakbot
2023-05-18Hsvu.jsjs 170ceff8d051e5addeb6beb1128383fe814b7b40738b54c0f99409de5ccba2c6Virustotal results 25.42% 
2023-05-18Ggzcmag.jsjs e5f9fc33236b5ba2988d71e8585b3802d96cde07263ae499ce6ac56cc9db183aVirustotal results 27.12% Quakbot
2023-05-18Lnwl.jsjs 03de8856a9267b9e96c1454bd5a13ff8d068076ae6a1b7ca1984367997fa981en/a Quakbot
2023-05-18Bhkgr.jsjs e8cadb2bfe88e91c6f0a88fbfa3c83c7cce944155ffde2920ad925df8ba77f75Virustotal results 24.56% 
2023-05-18Fncytyhy.jsjs 47838303934003e958511bf93e4b40816c144d7ddb6c99ad7cdda7145ee5dcf8Virustotal results 24.14% Quakbot
2023-05-18Unbzqhli.jsjs 5e1581b1da5a05a5baee064cf15334c7199e5808fcb9b16decf62e6cb66940c5Virustotal results 32.20% Quakbot
2023-05-18Zpakdkmi.jsjs 872a8726044bc6afb068028c44ba1376f7a3a6835147e080a9c5b7de41d634afVirustotal results 25.86% Quakbot
2023-05-18Vobbvr.jsjs 62f72a40ec519cd843b1c38ebe9ee2be23628961bffc952c1da59c3687a87466Virustotal results 24.14% Quakbot
2023-05-17Rgoqrwxn.jsjs 36fa7b7d4e7fc7c9366c2fa6533c47fd96cdc2d9a6f2c3a9025fc4271c5d4c18Virustotal results 24.14% Quakbot
2023-05-17Fisgxs.jsjs bdc565778f51721f51d31d3a2fabe61b47bd3d921ace6ff98d7637b3cee485bcVirustotal results 22.41% Quakbot
2023-05-17Grieu.jsjs 88c9cde337f3a1dcaac0cf20b1b30b985ee5b11e0bd60b3b768a3f70751105f9Virustotal results 32.20% Quakbot
2023-05-17Oyjqqail.jsjs dff43d93176f7f0b50d2b960680eb78be307c219d3a2f9b42d969390818a467fn/a GuLoader
2023-05-17Taii.jsjs c419bc2833e48f8f26166ef911d3915be8fd0619ac6a0e0638813a4404df6979Virustotal results 25.42% 
2023-05-17Vzpentz.jsjs c5cd6ca0ca7e79a3c24d0b2e608780ee8eff700153663539c8be58f273a24565n/a Quakbot
2023-05-17Ktgp.jsjs f865f1501145c736f9f72ffa6b3431effc20f094261818dfc60ace530d2aacebn/a Quakbot
2023-05-17Gubkco.jsjs d7d49795e5ff5964679ef6f6152c04927aab11d05896677fb5dc0506a1776de8n/a Quakbot
2023-05-17Xckpqyk.jsjs d0efa675c9f24204800fae00011c812ba5af867900cc595bc201dc9c33484061n/a Quakbot
2023-05-17Vsbqmyx.jsjs c0579ca6f84d2d6347226cb62bc47b87850d5ee47aabb502b23f9c1aff6c44a3n/a 
2023-05-17Acuix.jsjs 7a68f25b32c67edcdd49504ed80ce286ab699b18d7d31f897e196e659ef861c8n/a Quakbot
2023-05-17Luxulm.jsjs b0b57c1d599d7a07030dd73ef30161ffee2d5a4e38b6084988fc925786307543n/a 
2023-05-17Wktikvky.jsjs 302b078fd95934715590c4ecfd0678db0f4de047c06367ca3d0021d35592525dn/a Quakbot
2023-05-17Paqtks.jsjs f55633e8e0e2e3c64c86a777bfb09626bc8da1c128be34c6b0d2d902998f5847n/a Quakbot
2023-05-16Hwlokwz.jsjs cf80824d2fdc7dca32ac7c84efff4c6405654fbf2dd30b6dcc3d67f9ef6748b9n/a Quakbot
2023-05-16Mtjcjszx.jsjs f66024a5dc0f05a43821db11f73c3a80927a308a1ff9fab406117012542d4d60n/a Quakbot
2023-05-16Sycwipw.jsjs 98047143757619f2f6585577f09699f2cdf04e3d2438573b3050f76a5e7006f2n/a Quakbot
2023-05-16Kyylctwp.jsjs c6c12a75b7fbd9c6ccb9e4a86e0ee057ba069753119c858db56320caeb481adan/a Quakbot
2023-05-16Vzkf.jsjs 9217bdfec50227bb68883ec29f5aea3009e4353db8b3db95afe31cd7a566a01cn/a 
2023-05-16Zqep.jsjs 8239fe8e014a500bd118f9d05e400845db6279a3332b0d6e7ff4b2fc97059598n/a Quakbot
2023-05-16Zgmmmacx.jsjs 9fb724606bc123d44a4cbdf8769269b7a4ae8883816bc126c81b342251e8f19dn/a Quakbot