URLhaus Database

You are currently viewing the URLhaus database entry for https://managementroute.com/tm/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634181
URL: https://managementroute.com/tm/?1
URL Status:Offline
Host: managementroute.com
Date added:2023-05-16 13:42:14 UTC
Last online:2023-05-17 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:43:43 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 7 hours, 34 minutes Poor (down since 2023-05-18 21:18:32 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Cfmus.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Oxuza.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Wuiebue.jsjs b53fdd1d1bd8e3a31f0e5bcc601054bb77298b58b049a05155c329bfab7448a9n/a 
2023-05-18Dbnncj.jsjs 34bf72fbc4370971ff89c72391aca2a8a5b37aac3f1cbb8f2ab5480a3df6ae0fVirustotal results 32.20% Quakbot
2023-05-18Mber.jsjs eac6096d9525ff200431210339d6a028b68233173ae11df47f57222dc631697dVirustotal results 35.59% Quakbot
2023-05-18Rzafp.jsjs 4765e3f8945205cf00c99d49497f3f90e74523fec9fdbd0bf9ea1f6163c07512n/a Quakbot
2023-05-18Nusutcl.jsjs 6f741f3bd19d3433e0618cd31b85f73aa09fb1dfe670c9e5a8e0ec01cf274495n/a Quakbot
2023-05-18Lgaf.jsjs 31bfb0e9f32a6891aa3b4bb9c1caeefec664295de95b74eccecf9eb67a2b84cbn/a Quakbot
2023-05-18Dcfgnz.jsjs 6325a36db9c4fb5af943871bce9ae9c80002f6d9379e71cd94bdefe0342b14f5Virustotal results 32.20% Quakbot
2023-05-18Pwjmq.jsjs 34d43862c3788ec764c7fb735ddcfc1f1712a66632a3bf7e8b83cadc98a6faacn/a Quakbot
2023-05-18Moxb.jsjs 134b8da7c15c769cdda57799cf4c8b3e35b0937c9709e7c8e13783183ec10341n/a Quakbot
2023-05-18Ckdkfzks.jsjs 9e158a8d22dc98e3ae057267f1f3abc2cabc910f829c052269762460d602479aVirustotal results 25.86% Quakbot
2023-05-17Vruvmpz.jsjs 1bff54d9504766a1b23df7d6c83ffbf3db9ac0d0cc9ded739c34a0f1114f5717Virustotal results 27.12% Quakbot
2023-05-17Dsdnrdx.jsjs 07d1842292aa2619ebfbb551eff5580fb24f945283f3de4298dc06f9493b6b20n/a 
2023-05-17Rmvd.jsjs 798823d6f774c2380137f2e4d5c8a16ea4cec5e96284dfed0891528bdf512376Virustotal results 25.42% Quakbot
2023-05-17Adic.jsjs a581d1bc0926e4888a7d919a2ec529d51e03862bf784ac4cd4333e3df168d239n/a Quakbot
2023-05-17Wbvpyakh.jsjs 3dfefc0e91ce9c601581448bcc12aa145f0ae317f0c3bf6cd09b4605cf679ce0n/a 
2023-05-17Otvgbklw.jsjs b94d221ea7f0f08b1e7acc3d0a35c0f6a1d99332b79f7fe6253cf78f9de51b4dn/a Quakbot
2023-05-17Asvep.jsjs e9ea1cd3994bfb7715fe4a75af02e70cec59527cc3008fa490db4f6bb7b28babn/a Quakbot
2023-05-17Trrempc.jsjs 60228c06067e40e58e3d14018292fd772ba4d89ceb80fc46b34d40bd67681831n/a 
2023-05-17Zzbkw.jsjs 1ac254df20e1ddc94c1e28e8b7c37713be3620387157d769fc5f2814d7c4872dn/a Quakbot
2023-05-17Upioeppg.jsjs 0d6833ef45bee3279f521d3ef6a80cb3c6344b4760cdfba2959938add6de3625n/a Quakbot
2023-05-17Wmbpxq.jsjs aa0e6fa372ee1062d3c3a413b48efc248e80cfd203900d1db4ff60077643e70an/a Quakbot
2023-05-17Kcmftb.jsjs 83e61b8a122451a7cfd1476bf44d68bb19d6207c3a4a5edf1b5c3b6cadb32b6dn/a Quakbot
2023-05-17Bweqetcs.jsjs 9e53c3d9ea590808e635559904ce1b8026cb75716ea98765832c27ca5d49cfb0n/a Quakbot
2023-05-16Dtnykihf.jsjs 4db67db5b8c467d914f7b9ea40140ab07fce894de8909ab1adbdbe34fccf5aebn/a 
2023-05-16Rcbn.jsjs 87bdcb066bb2ec10da6166984191670fe041d9b4cad7c952527298f1dceba2fdn/a Quakbot
2023-05-16Kofzuyq.jsjs c24c73b2d8d5c5c888fbb18f93eb473178458c8ef4c524d7d8d6770e00a82c20n/a Quakbot
2023-05-16Ipas.jsjs 0593a3a614228340ac5c5360cfe4bf9e82f53fdbf6c04b2d7e8581db278e1cf9n/a Quakbot
2023-05-16Whviaf.jsjs d6fbbbfe143dcffadb5564a256742d17884999dd7603fb646b70a9cf866a6dd7n/a 
2023-05-16Nrlbucd.jsjs f5f3733e30f144b6e9b7065904d3b2716f30830aa2c3ca1c5e2f3b18a9ef62bcn/a Quakbot
2023-05-16Hgpvvd.jsjs 1c70a026f4cbd367882347911b181cf7bc065b5edc802a4e52aba75c912d9766n/a Quakbot