URLhaus Database

You are currently viewing the URLhaus database entry for https://zulfiyya.com/sutm/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634327
URL: https://zulfiyya.com/sutm/?1
URL Status:Offline
Host: zulfiyya.com
Date added:2023-05-16 13:42:39 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:46:19 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 8 hours, 53 minutes Poor (down since 2023-05-18 22:39:41 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lhnwjh.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Nmamq.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Poqk.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Gfvw.jsjs 32710031ec413ee729da36fd1713be9e2c4fe40ec0d4117888fc4d266a059a62n/a 
2023-05-18Ecncdedy.jsjs b53fdd1d1bd8e3a31f0e5bcc601054bb77298b58b049a05155c329bfab7448a9n/a 
2023-05-18Xpzxhtkr.jsjs 07c7eed20a0deee08f2f4bcdaa5a1b077e9c5d50c6b1219c4082c3d54afc1349n/a Quakbot
2023-05-18Fjtxag.jsjs 8eec4b2ca78d1d8b62a875c3a6b16a0a9053aeaf65f1e6cca22000629ab71432Virustotal results 27.12% Quakbot
2023-05-18Zxhfwe.jsjs ca99a531b2e34c4f23683a2cf2f4a2e81bcb2cc4975ba287d0bc6ef71563472cn/a Quakbot
2023-05-18Epxa.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-18Dfknp.jsjs 8f29c702a43f99c1cfc18167ff61035ac4068757aba92e0eb5e9dde5ad72a0cdVirustotal results 31.03% Quakbot
2023-05-18Dyyyrnc.jsjs 35a99626b0db91409ed1ac874964033c1490a20549ae611e95fa7f81dbd98d44n/a Quakbot
2023-05-18Lgele.jsjs ec6f55b9c56d3dead8b8490dfbbcccadcdfef62b7d67c671b8d0ee9620f4b74fVirustotal results 16.95% 
2023-05-17Iidhs.jsjs cb296a47f490cbc70541030b87a0b2d9eb6c1253da849e9e37e7912f2fff796dVirustotal results 35.59% 
2023-05-17Ieajeou.jsjs 8e028afe5e530bff241456519d98c4afe35e4e8432ca6929cb4a327144ecb765Virustotal results 29.31% Quakbot
2023-05-17Xfedcduc.jsjs 9665c60390e6de64d398dc14f91957bbec2a396ca2c0ee79cde6f8ae0e2a585dn/a Quakbot
2023-05-17Ktbzbha.jsjs 4f9c04f40501ff342f07c66108d89ffff23f8fa85ac574a2829cd65a757aeacfn/a Quakbot
2023-05-17Iggzj.jsjs ecb53b7bd1821908e3358a50f35b5cc1aa92c43f7c190eaa7e0e473ca199dfa6n/a Quakbot
2023-05-17Mecs.jsjs 506d6f7370fc1f1367a79bb76a39e5ed1e2c5113ca286350f3239788538fa80bVirustotal results 25.42% Quakbot
2023-05-17Wwurqit.jsjs cee11dd3e06833ff80c75ab19feaefb05e62b347d9ed97e9ecb8f4ac5a889f95n/a Quakbot
2023-05-17Iqdc.jsjs ff503f3409232b2f65dfa721ae9eb966163c14ca2c12ceb4863c7d9bd0e48d0dn/a Quakbot
2023-05-17Cwrpowmu.jsjs c4b08f1cfbabb9e7d7c094809c0e5111d3f40e3136d711f9ad8e887fb7a02754n/a Quakbot
2023-05-17Cjunnjic.jsjs b9c01e9a7817eb5f77b3b4c7c9dac8c492582fb1ea69062aa9b854ddd1408732n/a Quakbot
2023-05-17Izzlmke.jsjs a56b28255bd04ebf6e08ef3d4d29e0439c67731d85d8efad0eeb2b28d170369en/a 
2023-05-17Yisc.jsjs 9a9a1460292c9b27845390b3fadf2760ebda7b9cf5f8867fb487c04dd0cdb276n/a Quakbot
2023-05-17Wbyppypv.jsjs 70b06a2ddc6d78d447617487c751612757213f82979125469d13d7db0c863c41n/a 
2023-05-17Nxqqoxn.jsjs 4c2def02fc3cd5086fd5c408e1a38eba286a2b8706863c32bd13036b8d46e6cbn/a Quakbot
2023-05-16Selx.jsjs bf5472603ac909d6c59ae9c6e2ebd7a3798395b7f87a679b3c61b3db7bb3095cn/a Quakbot
2023-05-16Frfaatu.jsjs e35fd2d73ace96fa9db1ee32579c508dda21dae3b0407a910e754573feff38a9n/a Quakbot
2023-05-16Blqii.jsjs cf18b270363f6b6ed833f5830326cf0eb77cd1b02f1574832727e69cfc91e5d2n/a 
2023-05-16Kskydt.jsjs 666a6adc429fca92066ef337dcfea3e9fe650f1a6bcee4e4394be7be15587602n/a Quakbot
2023-05-16Aaxupl.jsjs f166a3bb26195d2eec03463b63d585baefe8e7686d1c54508144f464ab2c3693n/a 
2023-05-16Mgoiyq.jsjs ea9b2dea0697d79dead940e9a81ed91724dddf352a357dc7fa8ff97675df9778n/a Quakbot
2023-05-16Deafaqvr.jsjs 5f90483edf800f965bb9748b97a7f91fec8138e24bbb7ec84dbe007654578506n/a Quakbot
2023-05-16Pulqfjs.jsjs c3f7b3c32234d5671dcb2cc67d04f187753a435b044cee6b0b41d810bfa79870n/a Quakbot