URLhaus Database

You are currently viewing the URLhaus database entry for https://actiglass.fr/nra/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634221
URL: https://actiglass.fr/nra/?1
URL Status:Offline
Host: actiglass.fr
Date added:2023-05-16 13:42:21 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:44:59 UTC to abuse{at}lws[dot]fr)
Takedown time:2 days, 7 hours, 37 minutes Poor (down since 2023-05-18 21:22:15 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Flptlnb.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Kiqkxrtd.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Fbzig.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Oqstz.jsjs 3c9f0c1b3c44e790181490bad095c80bcf686f0872db03024bf08f802acb0a62n/a 
2023-05-18Nfpea.jsjs bb118ed7175733d7b31163818a3948e5e35d0e3ab3627a549e93cf6afa196585Virustotal results 29.31% 
2023-05-18Mekhutqr.jsjs 7d4c05f2b21fe02c34ffc3bc7077929482fa7cdbc01c894e2647cf6e38ab20bbn/a Quakbot
2023-05-18Dclxvp.jsjs 4604c9a02925f680aa68df7691aab5b247d61f74fa2c2c261a58ed40e9680327n/a Quakbot
2023-05-18Yrjdr.jsjs 860e36fc5c8d21dbe486debbb3dc78ef1409446eb46d7c84b937f01cd3075364Virustotal results 29.31% 
2023-05-18Vsvltjv.jsjs 2ef6e700c619c1ace05075497393d8ac827d836ec052de9b6a71a0cdcd343141Virustotal results 24.14% Quakbot
2023-05-18Zafc.jsjs 6cb675336525f3ee63666c008f21faa80acdb6e41fec92d7d75201b385880e2cVirustotal results 30.51% Quakbot
2023-05-17Jialwtas.jsjs 77c78781fbf40291d31c545dd06a094505a49bd415cbeed6b922cafc6af07586n/a Quakbot
2023-05-17Ugtp.jsjs 874c90fd9f5dbc042d5e87dee75b68570376e628600a8d08dc1083545283052eVirustotal results 27.27% Quakbot
2023-05-17Fpcz.jsjs 7237114103b60a76ef6a67916d0d6fc1e14dc707087bd27684d1093748393f39n/a Quakbot
2023-05-17Enzr.jsjs be61952594d1dcb5774683bd939e4e278b596ba069248f2ff16fc39f2351936fVirustotal results 10.34% Quakbot
2023-05-17Uutqo.jsjs 9ac768cf3025869132bdb78aad3f4505cd8dd7e5ddc218e64d6645ba8db5e4f4n/a GuLoader
2023-05-17Tzpie.jsjs a87f72f4479c91e3e36a8b6a204a7d9169c1e604389f6818744f3bcca14fd959n/a Quakbot
2023-05-17Cvynciwt.jsjs a9c6050bc229b2d8d2b411d575194857f0f0b908185bcc15cd09d5c25f330867n/a Quakbot
2023-05-17Ugkxlzkp.jsjs f2a2ace114103a041e79ed5165b96ac32d3595aaa0c8f1ff92533be7728179a4n/a 
2023-05-17Mwxcpgeg.jsjs 7956a036f0132ef25f7475f53f20861234b8bde9970178a7c995495bc0fb6ac1n/a Quakbot
2023-05-17Mritzbs.jsjs 48951c37f90b09b6425eb950deff1660b1bd6f293c72ccf1aa7b5f6cd8ee979an/a Quakbot
2023-05-17Rspsymne.jsjs a3a270ef06763672943f5b298896855ad1ffc30720203cd9157b46a988028581n/a Quakbot
2023-05-17Pzzsfvs.jsjs e87e7095c07c787cde16356d09c869d9e2242a336da21d02d7531af4856c95can/a Quakbot
2023-05-17Akgfcpmx.jsjs 563ba7cc24d948ca67c4d60b64ce465752ca5e035873f8ba2c7690530f67e2c6n/a Quakbot
2023-05-17Xhpgtdrc.jsjs 1f7dfb51588ffd63594701ca13610c005b8f83e31dcc31a0371d5c3c3c6066a2n/a Quakbot
2023-05-17Mujud.jsjs 51108bf84b3c7057a93dd37821065e9a09c2e2ca894cb68746e3afe8e0886238n/a Quakbot
2023-05-16Udnurfgd.jsjs 987a0a7516b6a5d2a006a0a8a4f3d0de38373cc1e12e25c3484d0c32d9c85666n/a Quakbot
2023-05-16Dhdn.jsjs 9007f4d836bc73490740e0350fabf4597c2dc0a6a1fcc0706d4c094535629ce3n/a Quakbot
2023-05-16Vlotaljd.jsjs 87c3c995eed7cc5abd6912bba9c621965b0f2ae8850be8ba0d36a36e3628ddb0n/a Quakbot
2023-05-16Hlwp.jsjs e38adec47bb83ee6b5ff1d8d1128a3e6a2a6d14b0da88ac251030aa50971dd1cn/a Quakbot
2023-05-16Bulhp.jsjs a2f24380cf6be05f59e5bf63d1adebb71cea74f31b042fb53b7c01b53d456d7bn/a Quakbot
2023-05-16Nxgi.jsjs 68e39db4ba928f7a74423c250e2af27f7bc6e1c16728de9f9fad3bf5968a7ac2n/a Quakbot
2023-05-16Ancqixu.jsjs c42bf49ef840356741bfefc26076eec472f085c8dfffc5bdb8df998c3c313755n/a Quakbot