URLhaus Database

You are currently viewing the URLhaus database entry for https://strategydirections.com/ip/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634317
URL: https://strategydirections.com/ip/?1
URL Status:Offline
Host: strategydirections.com
Date added:2023-05-16 13:42:37 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:43:44 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 8 hours, 23 minutes Poor (down since 2023-05-18 22:07:30 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uznvue.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Iaoano.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Efyjbed.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Bxoqro.jsjs 5f50afbc55f67b317da77cbd15af05226848886af2c37d059c4f6e334c33a326n/a 
2023-05-18Iggsmdn.jsjs b77866fad79584d4eeba2fb19ac488731b788c0c7c1ca30001f91741db44e06en/a Quakbot
2023-05-18Szyuxcx.jsjs a569ce1eb1902d2edf7cffba78e832e764170e48ecfe81ac3adda07c5f42455eVirustotal results 30.51% Quakbot
2023-05-18Zeqcv.jsjs b45fa98328f6170801cd88be88f4ac670f2266e2ed383e78f37fdd5d860dc695Virustotal results 30.51% Quakbot
2023-05-18Pqqmwf.jsjs 2810143d11f9ad7077972f807f2dc04a3f22746f81b7d8365d879e722c0b3551Virustotal results 17.24% Quakbot
2023-05-18Adjytkxk.jsjs 0c7ba195ded6d8e316021ca662000aef82b48c95dffdd60c2ea37f1849c555b6n/a Quakbot
2023-05-18Avsuefqu.jsjs f1cd10870a25ff5450774a8498966cb5bddf350a269b79fee66a198f6cf3b7a6n/a Quakbot
2023-05-18Yhuw.jsjs 875bccb572b756073e35cf697abde47c18a8fc4156b093bd6d229ef766faed99Virustotal results 28.57% Quakbot
2023-05-18Qcasndx.jsjs fab89deda2e8de1afcdf4d43b713652dab42ebcad6b4eddcd3b225188a7e3078n/a Quakbot
2023-05-18Ormorjxf.jsjs 0651c77d8fadac8f6e3798ca1534ef6af11482867d22cfb20df41d868c3cc727n/a 
2023-05-17Jgnax.jsjs 9d4e35c32d73270df3c5bf64cd693e2933e614075af8f15eeacb3fcd142f8ceeVirustotal results 28.81% Quakbot
2023-05-17Hfdcrkdl.jsjs 0692b014bee9b6b1a01cd4fcf3293e88388f98fb01460d6ffd2b3415d5de9779n/a Quakbot
2023-05-17Thgn.jsjs 0c1a4acb8216ade3632625958fc7427a5f996f5570d05d649a0e49be5e748ee9Virustotal results 27.12% Quakbot
2023-05-17Uiia.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-17Aizbth.jsjs 2570cf55120f499263bb8841172328a59101385bd1804bb919458e9bf167319bn/a Quakbot
2023-05-17Ahdp.jsjs d112f357338680817dc9cfe7ce64d7ab03de74008f16c43f1ef94b38bd159af8n/a Quakbot
2023-05-17Sfko.jsjs c1c25860d992cd6dc9b9921099d94bacf1ab089b4972e34a164fa6cb56e43e7an/a Quakbot
2023-05-17Yxjf.jsjs ab63b71e11441328677048a45ffd54e59e475be68edd55803c7c488e834d48ean/a Quakbot
2023-05-17Nvuvuo.jsjs c18dbd9b9b1bd282b95e760af3d9ea2ec4d689a2a012fe996c8dd148341f1ad7n/a Quakbot
2023-05-17Hpfx.jsjs b15b11e11df4258b5971d18c1f2453c56a484771659773bb20de826d1ab9966cn/a Quakbot
2023-05-17Pieincu.jsjs 5c31f3a3544277be9479a6bfc18612f766b4fa700b20f12f9581031a57d45578n/a Quakbot
2023-05-17Eudz.jsjs 7b5ad4506af8be417f875dfe2ff5b666ca3972f6edaf6c010d395d0428c3ce81n/a Quakbot
2023-05-17Bidkxxod.jsjs d4cbf24cd239dae42a43d438e153148aebf3ebe137c501416552f618cfe9413cn/a Quakbot
2023-05-17Yaqj.jsjs d8d1e95f2a66c12a997e5e890e589059649359a1d88006572c7f4beb2eec4af9n/a Quakbot
2023-05-16Lqsuqtj.jsjs e60284e592f9034d684a8a16a3ca410d542eefbb41b0c3822b960f24421421een/a Quakbot
2023-05-16Xgzqnlw.jsjs 46424e78377716734ad75bb9d1c24d82e8d3deeed48a401a235aa0b03e794089n/a Quakbot
2023-05-16Hqrhwbz.jsjs d49bbfad54b875629c81e859db2fe3eb072c4e7c77a3269dbac1494d6e5cfb26n/a Quakbot
2023-05-16Aoyfz.jsjs 757ad4f2a2fca066177c50dc35bb4d3a6bcb1e2a235ded95596847ad88c2341an/a Quakbot
2023-05-16Uxvhroy.jsjs 2d0b7fb73c1a13dbddb1269b1f8d6fa8b3075bb419ce43d6228b54c338cfa1cfn/a 
2023-05-16Tryi.jsjs d007203379ed2b57792f3279519aae12ed0c3a2c0900c1d58e7b194473dd9bc3n/a Quakbot
2023-05-16Bblp.jsjs 8580b18def80bcb09cf42c1acb75839ce0e7977db1cefab781468dab17bb2883n/a Quakbot