URLhaus Database

You are currently viewing the URLhaus database entry for https://kfcacademy.com/niu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634204
URL: https://kfcacademy.com/niu/?1
URL Status:Offline
Host: kfcacademy.com
Date added:2023-05-16 13:42:19 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:44:41 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 7 hours, 25 minutes Poor (down since 2023-05-18 21:10:12 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qgrdar.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ycimmo.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Qjmbq.jsjs aff635e43a0f98da78c09b60e347df6f804724aacfde8f69db8323e80c76fdfbn/a 
2023-05-18Sjnyzdz.jsjs 00662b73e2bd3a971290d1314c7c89f0f6d0d7244ebb8fde1721be20fa50a8daVirustotal results 30.51% 
2023-05-18Wyefyc.jsjs a64cebdd853596ce95beeb112b9dfab6eab26ff09b77eaad1c909cb1b6cff48an/a Quakbot
2023-05-18Gqzrygfp.jsjs c7164e6f2a5f4d34a5877e5de94ba49af13d9b6e10be7158adc9e0d267084c28n/a Quakbot
2023-05-18Kwmbw.jsjs bb118ed7175733d7b31163818a3948e5e35d0e3ab3627a549e93cf6afa196585Virustotal results 29.31% 
2023-05-18Fmjjty.jsjs 831bcd763103748a036135443a32ea80a8d0c311ba22872149bffc13eec6efc9Virustotal results 30.51% Quakbot
2023-05-18Wujoyarj.jsjs c183dc69a6e054260b5800df8cb1bdcf33338ca9f2d92f1b6d2161ca1fa1b850n/a Quakbot
2023-05-18Bfoamhi.jsjs 53182e2434b52d11490f911c908c6c23755d667fca1a03ac5d4be2cc9b0cd61dVirustotal results 23.73% Quakbot
2023-05-18Ytwzxrge.jsjs ba7f993248a05baa4fc8af51ce3e8f89889e817065c4b964cb37bfc088ae75d1n/a Quakbot
2023-05-17Oypg.jsjs 8ee5d86b74cd803753d211be4c64578d8d39e7dd487d114bdbe044505063bb7en/a Quakbot
2023-05-17Ovrohl.jsjs a2f17ffca655028bf5663349090771ded5e0eac6f65e71d0fc151816a2dc7342Virustotal results 23.73% 
2023-05-17Wuktj.jsjs 872a8726044bc6afb068028c44ba1376f7a3a6835147e080a9c5b7de41d634afVirustotal results 25.86% Quakbot
2023-05-17Yxtn.jsjs a70e07343087b1341505ab67207e4f4d1170a7ae25f9b7c90ca2eab5663e3db9n/a Quakbot
2023-05-17Cvkjtgvq.jsjs 4ec189841fea600476bff49f643d0877dcdc3e3050e54e56abc5a7c492ed00dbn/a Quakbot
2023-05-17Piwfps.jsjs 8c4f0c45a34f4cd509c3354346e0db29fbbe4bd099e2b67de6abc88dde35081an/a 
2023-05-17Bojhufrl.jsjs 4a5bb0d1af42aabd643a23c518cbc77c4a2931fab8d180bbad1c0ea815f5954an/a Quakbot
2023-05-17Njqq.jsjs d727023a68ba40889c0c17d7e8183a9ceb1517f7fa5bcb009462cc6537336e19n/a Quakbot
2023-05-17Tsfrvnpy.jsjs 45e28eb0645be3b7796a51344db79a4830e0ac7ab8d3852068f6148a341d647fn/a Quakbot
2023-05-17Hfzyczmd.jsjs 5f1efe761d078d991c97e34387b64e167312da3e7a53fa8fb4d03706e7a265cdn/a Quakbot
2023-05-17Cazdjr.jsjs 1227204a99c38ee1f8e7b84312e23b4f6becca63eca7044c62983912c112d6can/a 
2023-05-17Kruujw.jsjs f16acdcd620a085f31fbafd8cc1d274a3d556579df94780f5cc28c519399fff6n/a 
2023-05-17Ltvksmn.jsjs 4bcf2ce05143a4fbb41aa94083d3e25a3d2c4a3c53081e3c83294a7955bbff40n/a 
2023-05-17Epodm.jsjs 3e768cbdf582bdb7c16dc2e0416f3d44a1bd1c102d29c956a8a43c52364c3fd9n/a 
2023-05-17Liuypnh.jsjs 09dbc79c80552963c57414c1c528407b026cb6442d579db1604d345d19ed7334n/a Quakbot
2023-05-16Kcortgfi.jsjs 863beb7a2ed4b4ab41b35bef93f7567eb1d8fd2017bb13d24cd187d4942cb273n/a 
2023-05-16Kdevjumu.jsjs 918a9a37ccfb0fe7ee971e4f66630039dbc8eb7ab72265e784367fe7b8255331n/a Quakbot
2023-05-16Izuxgx.jsjs 02faa5dd52673c7cf2dc9a4583667884c0b54074092af69b6d34a91cd903c9abn/a Quakbot
2023-05-16Sxvan.jsjs 028a1c48a805fe3a16eea04b2f22162df40dcb1f7e313b6cb44cc31761bc58d7n/a Quakbot
2023-05-16Luue.jsjs ffe0896ab5f31518914c4283d7bd502fde1a3f8302cbd0c7cb0cf67d6e35b2c2n/a Quakbot
2023-05-16Ownhopje.jsjs 36952058e95289136e34c13fb1cd4706d4c1069733db76e8e36ee0aa5c41cd73n/a Quakbot