URLhaus Database

You are currently viewing the URLhaus database entry for https://globalchoicecourier.com/uu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634514
URL: https://globalchoicecourier.com/uu/?1
URL Status:Offline
Host: globalchoicecourier.com
Date added:2023-05-16 19:10:17 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:11:14 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 3 hours, 35 minutes Poor (down since 2023-05-18 22:46:49 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Akwsf.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Lxcxjvpa.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Jfaebzb.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Inmbmeyx.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dn/a 
2023-05-18Yzgkul.jsjs 53135c5a76b5107f70f33a158bd1f93695b5083eeea2d965eee9afc7dee1a829n/a 
2023-05-18Victrrw.jsjs 812cc57a966264823ac9c3e7a2ec885f1ade0a4a304ac4ef12554bbf9328338aVirustotal results 25.42% Quakbot
2023-05-18Fbcmrzx.jsjs f91b22ef75c62115177abfa54ffc898319098f3de31ddf0b2a964dae96c3b376n/a Quakbot
2023-05-18Tayen.jsjs 6b01b5522683c655f6e33fc4ecfa2ef55bae886a543ba306b61dd976a892fe96n/a 
2023-05-18Ocslvf.jsjs b246dc6bd29b7f7bf62fa6cfdb10a17053bed892c03b79d0328d384cf96f799an/a 
2023-05-18Ymgpuj.jsjs e1f86c377a5fb822c6704735ae1fc4f80bddbea822ee597fe99762e575e05ba2Virustotal results 25.86% Quakbot
2023-05-18Seykzat.jsjs bc85062a6ed96ba55f83637c5941ebb10dd8734a7486eb2e716a41e21578b347n/a Quakbot
2023-05-18Nejaoel.jsjs d5cf74860b7b3a07c522d435a8360406d7c4a5575bd34a1244d8d0c1426bdb61n/a Quakbot
2023-05-17Qvwwjk.jsjs d188bb106c47296a6f358dc69226ce3c9b48abe1399e7cf924fc4afa813b1505Virustotal results 30.00% 
2023-05-17Tqfl.jsjs 76b1f9267eb932c85c8717778e7399af2196f31c3f1ee4b76d83a2cc5f2e486cVirustotal results 25.42% Quakbot
2023-05-17Nvwlkr.jsjs 5c53fc6d6d29d37ae644bf3845ff851d6b03cd26eb5e411f93c26dcf018a4c35Virustotal results 25.86% Quakbot
2023-05-17Mpgscuta.jsjs 7fc4905fb7d4a1e1c931e869fdfaabceabbdbf242ca9e35ff7178f74e6f7b207Virustotal results 25.42% Quakbot
2023-05-17Oygui.jsjs 1d2471f7acbab8882ea6f628275c501f0f81e0aeab5ee16537702bd849e8ba6bn/a Quakbot
2023-05-17Tcxj.jsjs c5a390d1bf67c2241e5a9cb33cab3e83b41d4319c494c9f15d864cff3015e95dVirustotal results 15.52% Quakbot
2023-05-17Dxztf.jsjs 93492712919e0adee85ebe16363f99eb8fdbfe7f055f8645bf21322ce803cc13n/a Quakbot
2023-05-17Fnezajl.jsjs 41004cb0d270673cab3af5cab1a87b9c6c88fd3a43f9a28494997c13652781c0n/a Quakbot
2023-05-17Fpadhlb.jsjs 4120606e9713fc2c6475991b277e620d201eb93435b12fffead4e3640be0b7f7n/a 
2023-05-17Okoankzx.jsjs 36f1f35cc673871bb493328aa3ba3d74a4b97f47fa0054500c5b1faefb51c627n/a Quakbot
2023-05-17Eooyrrag.jsjs 9c8cdc227a8036d4385f660c1fe008a58614ee4922287148e0399571aef6d646n/a Quakbot
2023-05-17Lnufc.jsjs c48754b025e1e27e7b5ed34e0d4ba32d05f53753088b2122f6a25b2553738212n/a 
2023-05-17Vzgzhify.jsjs 01ba8434c34dd0dba4599a19bb4349e9fbfd7ced0f9c5a3444dc1945bdb23373n/a Quakbot
2023-05-17Urxippz.jsjs 3635e5118f7c018ddaf53cc1d32f31e20c6ef66493bf4b78883bd03ad69ae765n/a Quakbot
2023-05-16Udntwwtf.jsjs 0de913bd75b8028f2b0fb0a0ce2ca34c55e746779dc2cc444426cbd0ce1e4626n/a Quakbot
2023-05-16Mggdrytn.jsjs a0eb59c4803ddca1f9e6ebc12c4f9abd6aef1ed5f83fc7113154567d8a864d34n/a Quakbot
2023-05-16Oflm.jsjs d93d702fdc6e5a9227b22dce31f5eec728993a5f78917a14e1edb3001d0307d0n/a Quakbot
2023-05-16Xcrxsgdy.jsjs 8a270d79f519300172a738ff9ce443b6dea5ccc356be3cf62fe8c649bad8aa75n/a Quakbot