URLhaus Database

You are currently viewing the URLhaus database entry for https://cqfdpuno.org/iums/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634483
URL: https://cqfdpuno.org/iums/?1
URL Status:Offline
Host: cqfdpuno.org
Date added:2023-05-16 19:09:12 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116744 created on 2023-05-16 19:10:05 UTC)
Takedown time:2 days, 2 hours, 27 minutes Poor (down since 2023-05-18 21:37:08 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Drbdvw.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Ulqcjtsr.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Zkyarwxb.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Bkcp.jsjs 6cc01a25496eb11a08c19be9863b5a017888d09896fc166530e0d1afbf81fa1cn/a 
2023-05-18Mdcpnpmb.jsjs deeae69c4717d775bf5fa189632028d3bea8fff66b068f15bb1c163430d3fb84Virustotal results 28.81% 
2023-05-18Gaiq.jsjs 4740733be7e52c249ac1279362bec08d1af06172836e48e8e4d016c679ba2c01Virustotal results 16.95% Quakbot
2023-05-18Tilnvzuv.jsjs 31bfb0e9f32a6891aa3b4bb9c1caeefec664295de95b74eccecf9eb67a2b84cbn/a Quakbot
2023-05-18Zgopxeif.jsjs f744aaa7347e22e22b0047605341e57c431a9dbcdd028ca5713a221c51107aa1n/a Quakbot
2023-05-18Rvdtfc.jsjs 36c1b7c7a1b5c11ac465725f40b235b232adb02f122a1d9d3210656cacf4ee3fVirustotal results 25.42% Quakbot
2023-05-18Vniru.jsjs f80b9a7940830c735c2fbaf225da18389f25dc1ed7ef8e073311c9b3d680a95bn/a Quakbot
2023-05-18Ombegan.jsjs 69d10bf1c18cc7df540de106a1056c5af79f8b60f1ffae762d06532cc84375d8n/a Quakbot
2023-05-18Rbkdo.jsjs c73f356c704556ac74d752c91963fe6a1c7273b77027b218016b83f03ca878eaVirustotal results 27.59% 
2023-05-17Bpyerf.jsjs a23cf11c2f986f5d2412a9c98d50dad0b0a02cd2dbbd6fdb1eb47c20cb7dd2bbn/a Quakbot
2023-05-17Glzyzb.jsjs 13fa98699be69d8a22ee7c59e1a9efe2f504a721757490445465dc8a1de1765en/a 
2023-05-17Iaale.jsjs c408bd9762412a5776d177862b5ac082170428db1332d9ba6c28929b506a4858Virustotal results 33.90% 
2023-05-17Fxob.jsjs e0a76560e4dfa1a02a0ed9070737950e644f0b851388f7a580a8c384ba1ae3aan/a 
2023-05-17Cehfgbjn.jsjs 655729ffaa1d79b40a1df6017495f362432d5497a1c79b18220fdcc46d21f2aen/a 
2023-05-17Ldobzim.jsjs a18a3c0e37cfc92a00d139f4aebd7996690f4428dea318f028570bf9037d8aban/a 
2023-05-17Udxl.jsjs bc08bfae3a441cb9485634aeda5f5ae4cbbe5e36cd98ce7b2812cd62ed4e5034Virustotal results 25.42% 
2023-05-17Jxldxo.jsjs 9695d2ed6261eeebd78cdc70e45105cb68ff36705197941a93e942a4f861ab3en/a Quakbot
2023-05-17Xgfwbpv.jsjs 88c77f1ee7dbf97106671bd2b2001224709a49ce01019d729d1564ad8aec319cn/a Quakbot
2023-05-17Yfgc.jsjs ad32bfce3921748f1be261b7e66d6455de05b920fc92dc6ecc74ebaab64cbf72n/a 
2023-05-17Vctfyeup.jsjs 676c7be3ef6d295bb64c5a5de48b9fddf507883d99d97b101452a9e070dfaa0cn/a Quakbot
2023-05-17Twemnz.jsjs 037c6a376681be17b1cfba882641947243c354ac10681972586fae10ba1f280cn/a Quakbot
2023-05-17Zuiyxk.jsjs 436b253b6d46418e08cbc9c4eee4e1f2814aad8f59d5c0f7cff6acf98a0c87e9n/a Quakbot
2023-05-17Bodvgd.jsjs 5cf989394cca0fd7dd4d49a33c722f2807d0e61d47f30e7bf3ac21fc7b2d2890n/a Quakbot
2023-05-17Taptuxj.jsjs 0a0f2c13b2b44ea1d35f681938aacc9eeefc71dd6a7e1a7859186842d4a0bd1dn/a 
2023-05-16Qurjwl.jsjs 1d4a5226dc4262fc654399a7235e9c497a8416d76e6befbb550deee59133eb16n/a 
2023-05-16Tmhls.jsjs 4faf75c5b84ccd2c47555b9ca2f31ba89f91ecd2da6365828057bf50235c7d4en/a Quakbot
2023-05-16Uwszuprr.jsjs 7979967102c2de324f79f4fdd576140d4eba44295485e197ae3138ddbd601707n/a