URLhaus Database

You are currently viewing the URLhaus database entry for https://darwinrhodes.com/ui/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634174
URL: https://darwinrhodes.com/ui/?1
URL Status:Offline
Host: darwinrhodes.com
Date added:2023-05-16 13:42:13 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116550 created on 2023-05-16 13:43:06 UTC)
Takedown time:2 days, 8 hours, 49 minutes Poor (down since 2023-05-18 22:32:24 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Divn.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Vstauyk.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Eppoyo.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Qlgifo.jsjs 44b8968f1152c2cb2805a440d7e2b2efab187f4bb17ebc21b8079c84ae91b4d2n/a 
2023-05-18Cqeqydg.jsjs 0c72f8db70d3f144ec7cb21515e337377b9aa689dad88dfbf1720634c8b70453Virustotal results 30.51% Quakbot
2023-05-18Cqyoe.jsjs 176082ec2166a938b76477a4d42d940987b38d787c43628c9e17e75057338dc2Virustotal results 10.17% Quakbot
2023-05-18Olutwv.jsjs 5e580c21deb2f7d63ad49462e90d33c85c35e0b2c3f49ffeb5363cd11e8e9ea6n/a 
2023-05-18Rolpjx.jsjs bf6a2013ee6092e2d291a06d2f69e617b318a1e842a0d559b91fa1b8f8ea1a1dVirustotal results 25.42% Quakbot
2023-05-18Xvltnpey.jsjs 55de6657c16f6c71d27bc0cb38580d689241943b653c659ae89fd4b63fdc279dn/a Quakbot
2023-05-18Awfk.jsjs f11d7ad43d7a6c6cc716d06a9d41c96156d6ce0dc45d6add8d3039cae526e350Virustotal results 25.86% 
2023-05-18Ousks.jsjs 6be55c4c2824a4cd16aaf9002adae153b6156ce58174febfd162d82dff7ba019n/a Quakbot
2023-05-17Oujkcoob.jsjs 654d79d5b714216fcec5efd06082250b58afb76155c0be229ba139acd68d0797Virustotal results 25.86% 
2023-05-17Tgyzqk.jsjs e4a27492752db4f16d33fd2962a507bbf88d2a2714ae618f3dfa598bdb44db2an/a Quakbot
2023-05-17Pupp.jsjs ced3c62c0b0eb34cebf34dbcc0ee8a52ffec9388cc383952b09c7aa421199a79n/a Quakbot
2023-05-17Mrlgxws.jsjs 479435405ce11b58fbf16a8d7d4f3f1b2d8952718a2dd79f8c0e4ecb91176be8Virustotal results 32.20% Quakbot
2023-05-17Mupt.jsjs 5b34cafeebdc336b994960dac5ba4fcb70877967e1b19443c512f0a0cabc1d75Virustotal results 13.79% 
2023-05-17Tftza.jsjs cb46274d330ebea266c559fd5e391bd171816f40b8a0d960dbacf22c23a94ea3n/a Quakbot
2023-05-17Skxxgfs.jsjs 77c78781fbf40291d31c545dd06a094505a49bd415cbeed6b922cafc6af07586n/a Quakbot
2023-05-17Sgymff.jsjs c5a390d1bf67c2241e5a9cb33cab3e83b41d4319c494c9f15d864cff3015e95dn/a Quakbot
2023-05-17Vqgvocut.jsjs 941c4e06ed18c6a5bb923e508b8c9d274ba7d8fafb8ad2d750adbb4769ca59den/a 
2023-05-17Pnxehh.jsjs 0f63957b201136985c634aba1861a8accd7f7e7c7d7d46bd6aae2f2a8fe5c0dbn/a Quakbot
2023-05-17Ayiknsr.jsjs 45c1b1e2f43c938505ff0527371fc11752b2d7d44073522b6b41c9f4e1b9ef05n/a Quakbot
2023-05-17Amqeipmk.jsjs 0df03c849de71026cf89edf9ded64ea206df83976730b124a750ff8c4cba88dan/a Quakbot
2023-05-17Oaxob.jsjs 70c58ece9ca25046aff9377b344dc2729a691c93a9a8bfa589ee939f23f7f8e7n/a Quakbot
2023-05-17Wyjd.jsjs 646db5b52ff6691991fe887fdd5cd55bc7dd90ff9391655ff7f2251c691fbe0dn/a Quakbot
2023-05-17Ldbj.jsjs ebb1d413062ee617114a9f55b31cd2a86dfad349b8aae203cd18ea16410cf09dn/a Quakbot
2023-05-16Wahsdt.jsjs bd65f75f554f06d4e37ff077de57699100b02ff4a382e26795b0e54fc9320241n/a Quakbot
2023-05-16Ubgp.jsjs 8e12ebaedbec401305a9a41e3092e39372ddc9b4216d94fabf231cf23e337eden/a Quakbot
2023-05-16Xbozvk.jsjs 27ca078a2f06b589518a2f156073ea5e19094acb8d2550f8aaf3a54696a7e540n/a Quakbot
2023-05-16Fyfrhurp.jsjs 70d29d0fbe900153d8e73d5974c32093f5f66169fef858d2d9a24ba9fc026453n/a Quakbot
2023-05-16Fnkse.jsjs 4e5c909e2aeac66eb75eaa21dabe71c47e7628493bc7811b303b0a4851453f07n/a Quakbot
2023-05-16Kqdnhhd.jsjs a363173c4acd2c91ba3765a3dcf2612b2bba9ba96787e805a4a3bcb699a07c0bn/a Quakbot
2023-05-16Rkyapye.jsjs f6f6b20f9e76bbb8d01dd5282c1a21ec09b78292c285fc13069de1227d0f4f8bn/a Quakbot