URLhaus Database

You are currently viewing the URLhaus database entry for https://amsupplygroup.com/ub/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634448
URL: https://amsupplygroup.com/ub/?1
URL Status:Offline
Host: amsupplygroup.com
Date added:2023-05-16 19:08:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:09:17 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 2 hours, 25 minutes Poor (down since 2023-05-18 21:34:43 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Rwlozf.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Xxtkyfrz.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Zicjfzj.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Bbrloo.jsjs b499f7d9f3f301f1c742d78e70ca5d6c7f3311d85da230b809b9b2a02efe3662n/a 
2023-05-18Qqdc.jsjs eac6096d9525ff200431210339d6a028b68233173ae11df47f57222dc631697dVirustotal results 35.59% Quakbot
2023-05-18Sbdg.jsjs 9f9b7a0d9944437dbf0052fad1d08898979bd6c9a9d937a98cea3c757a5f15d0Virustotal results 27.59% 
2023-05-18Kaucjje.jsjs fb639f61394301ec51c3c82b270fa10118b12150f177db33a72560d80ad79f25n/a 
2023-05-18Luee.jsjs e05738fc1b53657500ed0ce0448f562aeb6e465927ca8d763f76dc97f3a2150dn/a 
2023-05-18Fhix.jsjs 8f360ef4554f315b708ec9a47229a77553d9764d491faaae0340e0e552551077Virustotal results 27.12% 
2023-05-18Usalkr.jsjs e193e117a9fdecfac181547ca4dadf85602bca2aad6bd2c6edeb2a25d45e9f91n/a 
2023-05-18Kmfhw.jsjs c408bd9762412a5776d177862b5ac082170428db1332d9ba6c28929b506a4858Virustotal results 33.90% 
2023-05-18Hwmkj.jsjs 8323339fe9864a8ae4d4d40aaccb4bf92a9b3ba6b545c2210dec09fb28bf9374Virustotal results 27.12% Quakbot
2023-05-18Sljxwpk.jsjs 939b394768f864f5af2b1e196cb9982563bcbf1157f23f9a873030ba262566c3n/a Quakbot
2023-05-17Wtdr.jsjs ad9d5d545cd208607067a384f752e68873813a4863a25840901805e6778a5f43n/a 
2023-05-17Srvqi.jsjs 555220330c615686c8a042f7d99f74d150a132b4d580ce95d1a7b6db412b77eaVirustotal results 25.86% Quakbot
2023-05-17Nbdcrg.jsjs 7f5092d0b223ae713b6ead45d62c1c63d910a500fc960aeae16e1a1073355c86Virustotal results 25.42% 
2023-05-17Hwbymqj.jsjs be61952594d1dcb5774683bd939e4e278b596ba069248f2ff16fc39f2351936fVirustotal results 10.34% Quakbot
2023-05-17Mfvpajwg.jsjs 962531faf5a4bccd1d88868db9f0b5a79c3073f110ae5e4b9f61d7ea15f8b855n/a Quakbot
2023-05-17Ejwelcm.jsjs b89d6433da85e8b53b60dd8f31aa096c923d9b4fb337c03d3b381482ef280974n/a Quakbot
2023-05-17Lzfwfrlb.jsjs 6900ebbc927522b18427eccb82c9ff5929648ddd932295399530b7a0c1987fean/a Quakbot
2023-05-17Oyztgzm.jsjs 891b02d63a8873f00468b05d3f7318b9e6a3d3a99eff41a8e3debf95823dfaben/a 
2023-05-17Unjgvwd.jsjs 90b47bce5b0c61fc318b1e228331d6a54f72408d9c02127672a6dc5a3f54e83dn/a Quakbot
2023-05-17Ubwwo.jsjs 5aeb91c12c65f635dd3b906a825eacc5ebb9c003d3e14946c51efa4631134831n/a 
2023-05-17Rqgclrk.jsjs fbb51fce204c3f16c42dfd328383b0d3b9edfaa6362902ed1ae53eac63c4255bn/a Quakbot
2023-05-17Byykczf.jsjs 27a0e59b6dc2242b3034c30538327366259a699d649559ca46c08f1843df444dn/a Quakbot
2023-05-17Xoexesx.jsjs d5cf812f5e8ad8b2f8a0da41615e933055bffea18adff90a37b3b17c97517c04n/a Quakbot
2023-05-16Cowg.jsjs fcadbf8dcd6d45707ba56593abc0d646ed1ad5258a7310d3e955393f87d6cfden/a Quakbot
2023-05-16Eiywlpsv.jsjs c6822ffb93e48d474530b6ea8226a56ac924a070243d99fbffaa282d6ccbd3ben/a Quakbot
2023-05-16Uuofm.jsjs 7fa316b362ac774fa29a5b3c3cffbf82cdf788e4b0113ed4ed772efb9f8602aen/a 
2023-05-16Xmmxwrps.jsjs 19fcd51ab4a2e904a77465600c5938126cc4bd52dcf157af3d19e0510a935e50n/a Quakbot