URLhaus Database

You are currently viewing the URLhaus database entry for https://thiscss.com/eo/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634243
URL: https://thiscss.com/eo/?1
URL Status:Offline
Host: thiscss.com
Date added:2023-05-16 13:42:25 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:45:13 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 7 hours, 27 minutes Poor (down since 2023-05-18 21:12:33 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nzbqz.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Brlsnnsn.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Ogou.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Grqegqa.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8n/a 
2023-05-18Sppkhr.jsjs 46bb768d9ae46d57ebe435af7dd325f9372338971a6ef491fde376fa8df7f3ffn/a 
2023-05-18Segy.jsjs 62f72a40ec519cd843b1c38ebe9ee2be23628961bffc952c1da59c3687a87466Virustotal results 24.14% Quakbot
2023-05-18Ueeuqzki.jsjs 8a1f226245e5f15e87409d617437e6d102c8267d28d1bdb3f198a89620b090edVirustotal results 26.67% Quakbot
2023-05-18Oxnke.jsjs 9ed630b44354fa9a5b12648e092b487dbecee08d6aad53bf5d2695dbea9b9cc6Virustotal results 32.20% Quakbot
2023-05-18Uqjlxnde.jsjs fbf34d1f59eea01ae0ec44fb3d7e93d4a06dad0b411065a5d6292f3ebe7081acn/a Quakbot
2023-05-18Qirfzv.jsjs fed0fa880fd9812bea44ff765356fb74bdc116ba4a93d3e22ad855b9e789e299Virustotal results 31.03% Quakbot
2023-05-18Ipjyude.jsjs de678b4a37c6c15a808f0289a0185302b696546ff234a9c180ca99ac8bb1f313n/a GuLoader
2023-05-18Zzlr.jsjs e78861a712a577b61558f7ea9878b91e974692081e5daa5f02dcb5ff1cdc359aVirustotal results 32.20% Quakbot
2023-05-18Cizp.jsjs 7ef24e8dba41a6e1f91b0d04f772ccc6300b92293dcb30726bd5052c1e2ccca0n/a Quakbot
2023-05-17Fbsujl.jsjs 759b7245c8f5cd0c5db7853442c740696c4a66caf8aae6a281b32f063f6c660an/a Quakbot
2023-05-17Ckwgfzwn.jsjs 683503e1ee6accf36b4e270156fa48982aeb9619157f07c35c1dbbfeb8a43e7dVirustotal results 29.31% Quakbot
2023-05-17Evgxw.jsjs d50736e0dc6f86a7295550e45d34bcb51be1915a810402b50f05881002c45135Virustotal results 22.81% 
2023-05-17Wcgsubxs.jsjs f4454d45458f3aaadcdfc328fc4107a6c670b1c0e04df1d476ca56e831b83818Virustotal results 27.12% Quakbot
2023-05-17Bvtgi.jsjs 2ef6e700c619c1ace05075497393d8ac827d836ec052de9b6a71a0cdcd343141Virustotal results 24.14% Quakbot
2023-05-17Rrrtcsat.jsjs e5c5a60b175cb60af996c9c06d7956eb02b365460e950ac7662bb4ea5c87d9c0n/a Quakbot
2023-05-17Pchf.jsjs fef7c15b6ad604bd018cde2f5440a4e04fbfb2866102378bd2ee983988efbd79n/a Quakbot
2023-05-17Tfurlcef.jsjs ed1ab321a38a90eb52cd8a94813e7789b76d9eef71d3dfe9ad0098e934111bc1n/a Quakbot
2023-05-17Wptr.jsjs 0c9f27d5a7e9bc50a2e31f03983c862a3337f0e359c6d2b32adc19f529aaa917n/a Quakbot
2023-05-17Fsri.jsjs e8c79edd951a1ac75e67ec035c4b9dcaa9dfe062bfe836b7fab19ef925438b2cn/a 
2023-05-17Ndwro.jsjs 8c9e6f2e400a648dcbe1159a23257d3be62f355faa923efe207793338754ce71n/a Quakbot
2023-05-17Qrgfs.jsjs c266abdca065e37174cac7403f44b9087b2bcd55826aee35b14ee366a287f6afn/a 
2023-05-17Yvlrz.jsjs 1867becdcfb6f553b99f1595dbb1258b434290e3b55b2ec08c36e4c5d459d609n/a Quakbot
2023-05-16Bfwz.jsjs d8250a95eae4bb91df08ec3f6e9892e6bfc336b25e906ad7d2f1e8f7408bbe33n/a Quakbot
2023-05-16Gtrxmay.jsjs 2a367707dc56ad19db2522810b7e223132cbe309f0930b3320fd7a7ae387fcd0n/a Quakbot
2023-05-16Xaajis.jsjs a446fbf825bdaf2421c223e55296ca01e32344a84230bc58747ffaba2db6a51dn/a Quakbot
2023-05-16Anxon.jsjs 813e18b70afb6dbca759cd680434c1c8bb327f4a2f9f9d4b18ac9760f343c9d0n/a Quakbot
2023-05-16Kjakbek.jsjs 474c0ea15b0df19fba060f896e4c571ad4c5890da420526e5de9b08835b0c0e4n/a 
2023-05-16Vvkunvdg.jsjs 61f6b20ff829fedddec659ce718a34cb05b6abd1142ceb0915aa7855b9dceaefn/a Quakbot
2023-05-16Ewhxbj.jsjs 1302a0c3ec367186f57a549a89baf966572298ccb8e740ba5cd221d7e52a4b6bn/a Quakbot
2023-05-16Gumqkyu.jsjs e2162d4716a8a0757aa4f5b2c74e7769216821ff81d5903c945c86ea5222ec75n/a Quakbot