URLhaus Database

You are currently viewing the URLhaus database entry for https://agnesdeicollections.com/sto/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634319
URL: https://agnesdeicollections.com/sto/?1
URL Status:Offline
Host: agnesdeicollections.com
Date added:2023-05-16 13:42:37 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:46:13 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 days, 7 hours, 39 minutes Poor (down since 2023-05-18 21:25:49 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ekngqvwl.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Qiftpz.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Xvfnvx.jsjs 452b99447ed9476fb4352d9bd0298977242a3fa07e4c1e9abd2774c225afaae5n/a 
2023-05-18Hgsiyoj.jsjs ad9d5d545cd208607067a384f752e68873813a4863a25840901805e6778a5f43n/a 
2023-05-18Fkov.jsjs b243ce7f5b24e6eab35ff99fcc718064f5897388b337460b05226b50e50b7dfen/a Quakbot
2023-05-18Wyvql.jsjs 0769e73bc4ebc2ee5fdfb2e6d02b6a282085b48c709104d96e856380e8e4ecfdn/a Quakbot
2023-05-18Jzmomtao.jsjs 4fe762f3bef37ff2896345d647489f0ee60515aaf5da2c93572e1088e91adf79Virustotal results 28.81% 
2023-05-18Jvbmw.jsjs 56e958c5170fa27748c823f1145b93644170f72706fd132b2dfeb286ccf1192fVirustotal results 27.59% 
2023-05-18Ayhzfmm.jsjs 91bf97c2e5d25bf79ff22ef99cccd3bdb7aab412d34521e172610b16562203d8n/a Quakbot
2023-05-18Fhas.jsjs 3f2b1d4fe71004830b3afc87d735391d7ff0033d3264baf0b9b84903c52c16f4Virustotal results 30.51% 
2023-05-18Jqhjhoj.jsjs 321c1a3f14a23d2a9aa660e3c3d41d7c92fbba4788fc20057ac697e402248405n/a Quakbot
2023-05-17Dwdlotv.jsjs 345e76a5091b5ecf319a57a8901fc203f48dae4dcc62b70fdc4d1e542d1a1f46Virustotal results 30.51% Quakbot
2023-05-17Lwtriphq.jsjs a22b66a10925ee0bc864c2b920e30792c9c23d171ffe1d926a43d0403fa0f1c5n/a Quakbot
2023-05-17Oblel.jsjs 7aabd12a63a4289e6a5f5fc62d866ed2ade8e917a6f2d203bdfd37c0f87ab265n/a Quakbot
2023-05-17Vqbni.jsjs 906e50a48250213ff6fa64b72219e204e4f47e919757a5b1214a5e7682a44da1n/a 
2023-05-17Nuyrbmu.jsjs 611f39b0fe3d00c6bc886929f93aab5028192d0d7398bd8621b700c05e99dcc9Virustotal results 25.86% 
2023-05-17Slpdrrlr.jsjs 4ca00c819ac67574145c0664985afbfd757621b4809ec157f14d22108aeacf8dn/a 
2023-05-17Dubcsb.jsjs 36c1b7c7a1b5c11ac465725f40b235b232adb02f122a1d9d3210656cacf4ee3fn/a Quakbot
2023-05-17Qvskyyrv.jsjs 8473f06ea508cbb3781b8df931351eba6f86fa9b22ac93727e6cb46a086fbfb5n/a Quakbot
2023-05-17Lvad.jsjs 850e8e43cf5dc3fe1b9b17f3348d5454781be61fd111d0a55de3859360a5f189n/a 
2023-05-17Clzf.jsjs 62d87a56669b34e3271d9b297be6d9ccf6feb6ad748e21ce7e22a11f1cb32602n/a 
2023-05-17Gpccimbz.jsjs 61098c3289e25ee950e930b7cf29046a4d194662b664607b4e8ce61d2f8852b9n/a Quakbot
2023-05-17Tnmckq.jsjs 83968e26527a0c995d40c4cc9dd34b99c077a8dbf20888ac7411e2326309ddb2n/a Quakbot
2023-05-17Bqqu.jsjs ec017322391e822ec88c9d5f15e5059bc40b131554964fd022878793336bb513n/a Quakbot
2023-05-17Tdhbs.jsjs 515043f61f34de4a5f6b93be271fa26c91a19e1e79cc255301629559c5bdf548n/a 
2023-05-16Qincttbt.jsjs d5a28bd25227f1a903b0654fb5856f0abf6fbc4c8c8a1841ae8f8e1e2562fe50n/a Quakbot
2023-05-16Delutlow.jsjs e5b62a526182d4003b3db8a84a922cfd997562c0c494f1fc74b4548c9bfe167en/a Quakbot
2023-05-16Sqhqx.jsjs cc9de203db9c201b027e28e697b8e524053a224564cc39482f1b765645028dccn/a Quakbot
2023-05-16Kqjixcr.jsjs 007092eb5c4b28fe40071e4f9d3c2d9ae12fcbe61c28b6052a3c22399d5c13a3n/a Quakbot
2023-05-16Ykhbcm.jsjs c8679a4b7055919f98f99b0196307ec3435395364f0d4c12d51837a6c634ab38n/a Quakbot
2023-05-16Tvmh.jsjs 56ac131bc47ddaa8ebbaa345a1ebcbf7aa1908b4744ea9cef58aadddbd28ef7bn/a Quakbot