URLhaus Database

You are currently viewing the URLhaus database entry for https://flixbawal.com/ea/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634285
URL: https://flixbawal.com/ea/?1
URL Status:Offline
Host: flixbawal.com
Date added:2023-05-16 13:42:32 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:44:47 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 9 hours, 5 minutes Poor (down since 2023-05-18 22:50:09 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nmrg.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Cttj.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Evmw.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Svwchp.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Pntxswl.jsjs 3c9f0c1b3c44e790181490bad095c80bcf686f0872db03024bf08f802acb0a62n/a 
2023-05-18Uqaaloq.jsjs 7723afb8d2a1417a6f0c808e628394b609e66227688064323ce47b25cb0505bcn/a Quakbot
2023-05-18Vfwgzqm.jsjs 17ee5a686914f6713574da4e30d7902af9bdfc03eb0173e1143cc97a4fa37b75Virustotal results 22.81% Quakbot
2023-05-18Kzpwzbq.jsjs b76a46e9b0db483e342c390f25663222fee2e67cb7670205636c7ee748850b86n/a Quakbot
2023-05-18Civmd.jsjs fbf34d1f59eea01ae0ec44fb3d7e93d4a06dad0b411065a5d6292f3ebe7081acn/a Quakbot
2023-05-18Dezidvb.jsjs 0b8b2630460c4baa473d458c5dfe165acc6e1cd41d684697d22599bce6fcf623n/a Quakbot
2023-05-18Hxrztz.jsjs cadf3b701a796ab414a9adb1d3c761ea95dd6b2b518dd9d9f1034a9982d8fc30n/a Quakbot
2023-05-18Vbqr.jsjs b726185bac5c9502b0014a711f793d0559b2d0afcaf5cc376d063cb315412020Virustotal results 30.51% Quakbot
2023-05-18Iqnkzi.jsjs 8cb9812b4c0409176b2f0770497520692218130496cf0a2a363b4606ce28f506n/a Quakbot
2023-05-18Clguj.jsjs dc0d873178c61dae13dac14d65611d4716e9c28ebfa216e32126dbdd1ac971ben/a Quakbot
2023-05-17Vytjxnv.jsjs a8a8153cceaada2e2ff92961844812b0aed9cd17ebb6700ebca64bc3627c960bVirustotal results 28.81% Quakbot
2023-05-17Onnkcbj.jsjs 9dc74a47b57fcd85200f975b411792401c29e5d1ac2806f4efca47c4fbc00eben/a Quakbot
2023-05-17Ofpnetpv.jsjs 8f29c702a43f99c1cfc18167ff61035ac4068757aba92e0eb5e9dde5ad72a0cdVirustotal results 31.03% Quakbot
2023-05-17Lgxsbvg.jsjs ea84f700c5132b793e8bbc20dd9383bd71e86ffe8be7ec16ec7fd5ada9cfb33en/a 
2023-05-17Bhguc.jsjs 502aa2d56dbba3e18971b863336aff4b696a67a0935ca0cc3d9186a3c2c8550bVirustotal results 28.57% Quakbot
2023-05-17Ssyanbqk.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-17Klbxjue.jsjs 1c527faebea66510912a82a4ece923294f74fa2947ce89b48b9b341ade828e1en/a Quakbot
2023-05-17Dlzwk.jsjs 61dace71f0db212bb57bcf2dbf762b571854a7473d047a427dece3af95aa77a3n/a 
2023-05-17Jnbhm.jsjs 5aba9d3b0cd8ea9eb6acfda996c3eabad9241d1cc6a246154767d2d5c4280dacn/a Quakbot
2023-05-17Yzkokm.jsjs 07fe0c6c251a3cb14183717fd1a19aa8f1cf260eb08937ac29b099450ba2bf03n/a Quakbot
2023-05-17Fmexk.jsjs e55c59e6c86272635325b410aa98597e4ecbdd405c612eb919f7e199b19705dan/a Quakbot
2023-05-17Uboqa.jsjs 4f5819cfecad6c07847b7d18c86eaf2732f757fe30c7b8c7eaa981fa2721c596n/a Quakbot
2023-05-17Mzfo.jsjs 10bdc870fce8f9b6a8fbb001b79d33344e3f9e44359562a69d116c4d7c8ca9e4n/a Quakbot
2023-05-17Fabzuhmm.jsjs 6820e92ba4f2570c6eca02e01013d5f453b8dc9ea308217469885ad3e763bbe6n/a Quakbot
2023-05-16Wbmr.jsjs 661c39f3b0d9818f184ac7b256c5cc3d16d052354f0f2afdebfb8931a824c883n/a 
2023-05-16Mdpoucx.jsjs 057551d183a465eb231df17b85d3323ad244b744dd089788ec88fcd10a2661a1n/a Quakbot
2023-05-16Oorrl.jsjs b911cd6eda1b5ff8863f45015dccbd9b56c8d0af307adcd0f603a874ec757113n/a Quakbot
2023-05-16Xndeybwj.jsjs 830dab05f6ec97e71ea59dd4edc3979ec27f5193f56348738e832b4975d37cd7n/a Quakbot
2023-05-16Lzwrmolj.jsjs 2a5ae4448c069e3245eedfb153563311c804190e5292877eb58eac64986eae0bn/a Quakbot
2023-05-16Ahbs.jsjs faab50a1b88639e41cbacda1e561cbb6d44b4fe3a981ad1c34d8440ba8794bb9n/a 
2023-05-16Alvlx.jsjs 86e15170c82279dc500ecb28a83044575704001c95648020a841970ca1a9b16en/a Quakbot