URLhaus Database

You are currently viewing the URLhaus database entry for https://carnefina.com/muso/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634187
URL: https://carnefina.com/muso/?1
URL Status:Offline
Host: carnefina.com
Date added:2023-05-16 13:42:15 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:44:24 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:2 days, 9 hours, 12 minutes Poor (down since 2023-05-18 22:56:28 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Cdcajb.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Owvtg.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ryyk.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Djzo.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Nilwaxq.jsjs 0426224c9d6035c408494c2b37300fb27436b1fb811ce72bd21755c12f0dc610n/a 
2023-05-18Vqnzxx.jsjs 3657123d41437d5c2c4b48b03e14153b367398907ae10d30021c974941a5b64cVirustotal results 32.20% Quakbot
2023-05-18Vcutxsbf.jsjs d6cb8ae70d4f102ac987c9de47abc6d962e10fa9755d74ea54a68edb6173dad1n/a Quakbot
2023-05-18Huvjcez.jsjs a99deed91507b2e0aa98b17753892aa733b12eed707f493c38359420a3a4f109Virustotal results 25.42% Quakbot
2023-05-18Bjlwshg.jsjs 3769ece7cf8318e31632260f0a962a6c155adc7adcb91cb53a6d50100a8f3281n/a Quakbot
2023-05-18Utmdjtj.jsjs fbf34d1f59eea01ae0ec44fb3d7e93d4a06dad0b411065a5d6292f3ebe7081acn/a Quakbot
2023-05-18Iktvp.jsjs 813efe88246132a445789b21b1536bd94263cd9a8c7623d7b96a9e5ac755d470Virustotal results 31.03% Quakbot
2023-05-18Mmhgjvlt.jsjs 8323339fe9864a8ae4d4d40aaccb4bf92a9b3ba6b545c2210dec09fb28bf9374Virustotal results 27.12% Quakbot
2023-05-18Rsbzk.jsjs 962531faf5a4bccd1d88868db9f0b5a79c3073f110ae5e4b9f61d7ea15f8b855n/a Quakbot
2023-05-18Jeqgvfd.jsjs 24c2f222f6f2809f7c5dda15d789a41d9424dfce3714fe71bed9fbb0e077503en/a Quakbot
2023-05-17Dkpdk.jsjs 875bccb572b756073e35cf697abde47c18a8fc4156b093bd6d229ef766faed99Virustotal results 28.57% Quakbot
2023-05-17Jdsihhoj.jsjs f865f1501145c736f9f72ffa6b3431effc20f094261818dfc60ace530d2aacebn/a Quakbot
2023-05-17Iawnsim.jsjs 1ef243d363359aa7c5d8ab0a55ffa52a9302f63a3750df5b8408c99641bb9ab9Virustotal results 25.86% Quakbot
2023-05-17Axkuxeyr.jsjs 029c7e0d1aaf9b325f8d1adf729b367d04954a895d6c1988c91f700855d91db6n/a Quakbot
2023-05-17Tnrw.jsjs db756aef0c52e6f31a7cb628eefe67b0cc7d656427dd2d71c87ecce62165b562Virustotal results 22.03% Quakbot
2023-05-17Ssihglp.jsjs 4fd5f473b0f97c7dcf4a244234c780051bb0e3c316acbb18b7f959a6663c9454n/a 
2023-05-17Vgzr.jsjs 720fb2e7a204367de578d5346bf193bee009beb5bfc5c54ba4349ed5aec8dbffn/a Quakbot
2023-05-17Asqiw.jsjs 9683f860bdb26e382e55c9e51ae61aed72943bc0fab70e9799f64fb129e03e53n/a 
2023-05-17Nrtcabqt.jsjs b558b6cc134bbf18ed1d3c08606d4585520a881190782a45a1bd62fb3a7e6c46n/a Quakbot
2023-05-17Xxkovrtj.jsjs feafbbe3bf89976471827c375a6a92887eeb46d37f9fff65bd999f453e92815cn/a 
2023-05-17Cjnz.jsjs 2edd76e6f7c99159c8818bf221559d8a14e285b0e7b475520bd77ccb61d56dden/a Quakbot
2023-05-17Nezlr.jsjs c4f82032565fc52d5fc217512543a8546c2547c34e39027c0cb21e832d9ec979n/a Quakbot
2023-05-17Ycgwuar.jsjs 80f05740b35b46c981559a03bfbb0a645a319660d6dc554d32b637c21dfdf1bcn/a Quakbot
2023-05-17Bbnkbfp.jsjs 8dedeb7fd99eb38f465a06ab886f9e7a028106fbbe06d77f4b9998e1bfd3e546n/a Quakbot
2023-05-16Ajiqdvf.jsjs d54fd4abec5b170f5ba683d910b6f71030cdf18fa61aa3bad4357bbee957e253n/a Quakbot
2023-05-16Yvnctnr.jsjs 49089d08a119c2e2527833fafdf0fb2e35024d626c3157a3d8c7877bd9fb9a63n/a Quakbot
2023-05-16Ggugmzrc.jsjs f59245225ae6a65e2c5bfc9aafe8b8c63e2314cb3b8d08e0889a6bb2633540c6n/a Quakbot
2023-05-16Hkibyz.jsjs 2011178e93e24656805391174351bd501f1459f2e58bcafcbfa5c0d93c3a5051n/a Quakbot
2023-05-16Eemkznfq.jsjs 70a239b6f2041540b90f4e470696a5c02e6c59b6d6fb04f3b5699a2f9a6fbbd0n/a Quakbot
2023-05-16Flftfpc.jsjs 49ee612006b86633dc09fb3df25b26f2218516d4824c2262154fdd110f74cd21n/a Quakbot
2023-05-16Qpvwloq.jsjs 5c819374511690296a9c8c6abed9e0dd392224df6b596e51020d7dba35fbbd50n/a Quakbot