URLhaus Database

You are currently viewing the URLhaus database entry for https://etiskin.com/ea/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634518
URL: https://etiskin.com/ea/?1
URL Status:Offline
Host: etiskin.com
Date added:2023-05-16 19:10:17 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:11:17 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 2 hours, 27 minutes Poor (down since 2023-05-18 21:39:09 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Dgndgrce.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Pinve.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Ssuvkfz.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Pldzmarz.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Umhomsj.jsjs b65cfc5c1f188f590ab7d7d6a20d1ea638a086a9be61e3442b6ea9388fda3c0cn/a Quakbot
2023-05-18Qtzka.jsjs f0071ab8efac63f43a57e5ce10cebfd8f2d18f0b8df63002a484d4acdc24b4dfn/a Quakbot
2023-05-18Ryeey.jsjs 7723afb8d2a1417a6f0c808e628394b609e66227688064323ce47b25cb0505bcn/a Quakbot
2023-05-18Xzldgbc.jsjs fc4e17680da39bbf2dfbf388da243c919927a825eca7d8de8a39d74be04968e9Virustotal results 31.03% Quakbot
2023-05-18Mtqxmz.jsjs 447b96999dd079d4e5bbdefc464fbae41be6c1d6f55fa0d6dc0cf9db6f3490b2Virustotal results 23.73% Quakbot
2023-05-18Paflgf.jsjs 6cc345a8ad3df8d8da07821f31095f9c217201e0065038c5bb7e15aae14a9035n/a 
2023-05-18Gwtsmpdb.jsjs 502aa2d56dbba3e18971b863336aff4b696a67a0935ca0cc3d9186a3c2c8550bVirustotal results 28.57% Quakbot
2023-05-18Ehqwibam.jsjs b246dc6bd29b7f7bf62fa6cfdb10a17053bed892c03b79d0328d384cf96f799an/a 
2023-05-18Vktqg.jsjs 345e76a5091b5ecf319a57a8901fc203f48dae4dcc62b70fdc4d1e542d1a1f46Virustotal results 30.51% Quakbot
2023-05-17Qrev.jsjs 8eec4b2ca78d1d8b62a875c3a6b16a0a9053aeaf65f1e6cca22000629ab71432Virustotal results 27.12% Quakbot
2023-05-17Wbnzya.jsjs 8323339fe9864a8ae4d4d40aaccb4bf92a9b3ba6b545c2210dec09fb28bf9374Virustotal results 27.12% Quakbot
2023-05-17Gfnbe.jsjs 7100bd0704b52e63e4581b308b07b43d48da5998a03a3ef43b8e78bf0d855d17Virustotal results 25.42% Quakbot
2023-05-17Sswn.jsjs 340674eac99b309a0a10a07f5d961e87788e88c4cc2f218da6cd61ccb196deecVirustotal results 11.86% Quakbot
2023-05-17Jtpv.jsjs 5e580c21deb2f7d63ad49462e90d33c85c35e0b2c3f49ffeb5363cd11e8e9ea6n/a 
2023-05-17Glgke.jsjs 55de6657c16f6c71d27bc0cb38580d689241943b653c659ae89fd4b63fdc279dn/a Quakbot
2023-05-17Socp.jsjs d8227132d7300d02c5cf46a7c7c4ea76a6fcd10c516382dad0a8892266612025n/a Quakbot
2023-05-17Kljcsrdn.jsjs 0d6511ddb8cf97d9967367c983015cc45c5ea8c7ae68416f28625637be59caabn/a Quakbot
2023-05-17Zpryb.jsjs ebdd9589751555b968ae793394b5e24dd715c8eeb7132bbc1f1e7931dcc50ccdn/a Quakbot
2023-05-17Qvse.jsjs 6e1bc7128a411ddeef7e0a8a210c388bd18b118d8b679ac6ed75c44fd54ed371n/a Quakbot
2023-05-17Puqwkqbi.jsjs 620026c88b61e88a2bf9e783193e763aac9fa5e4ad34ec3d1edf5da98a0444a8n/a Quakbot
2023-05-17Oyquvlu.jsjs d33ab6c292d58c75c33cd56acb302298e07d97ab6d415ec8436fea87f55eb58cn/a Quakbot
2023-05-17Rals.jsjs f99f9d0f4e58c34e94bafae18033bc760822b72bd90286bf0d61fd880af8ebffn/a Quakbot
2023-05-17Cdjhu.jsjs 661f643564db88656b48a6bb54966836f95216284a3036597c957fbcd29456b5n/a Quakbot
2023-05-16Scyqzzrj.jsjs ea10f49c2ece0588e580f30364f67952b787662502438f6b468a8d4c9f2bf4fbn/a Quakbot
2023-05-16Vpymoac.jsjs 40883e22cdda477d1acdfe1e061f737a2317e5737c46f75e7292df6246584af8n/a Quakbot
2023-05-16Xqbm.jsjs 5fe84b7aab8f519094da2d0d55a430bcd74d7f0d0ec4a18842b11f32860029c5n/a Quakbot