URLhaus Database

You are currently viewing the URLhaus database entry for https://ghdgroup-llc.com/odt/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634529
URL: https://ghdgroup-llc.com/odt/?1
URL Status:Offline
Host: ghdgroup-llc.com
Date added:2023-05-16 19:10:18 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:11:25 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 3 hours, 22 minutes Poor (down since 2023-05-18 22:33:48 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Prmp.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Xiypiku.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ikbcqs.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Sfcyxjle.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Iymx.jsjs 935e56d91107aeedfb71a87d995f9cee169fb8f4abf76aed50a05ba63e4b052fn/a 
2023-05-18Lnwaqbe.jsjs ccdc371fa95a2dc8192ecf73826f489942857addced0e8ce4b9aa969aa98381en/a Quakbot
2023-05-18Kdojwyan.jsjs 3938ff8a3f26ca0c121f461afcbf7394844e31d1fb9e68757fd98de2a4b3238bVirustotal results 23.08% 
2023-05-18Asqxwh.jsjs 93492712919e0adee85ebe16363f99eb8fdbfe7f055f8645bf21322ce803cc13n/a Quakbot
2023-05-18Qgbffdrq.jsjs e6823880248255f28dad73af6553cfbae133b6df9f78eff124a379d793265ac2Virustotal results 27.12% Quakbot
2023-05-18Kuwsb.jsjs d2338cd0376171b31bef79e7bc05e3954d3c61c6f23184804a1a1110dafa3d36n/a 
2023-05-18Rzmdm.jsjs f064ddce080fc01f0b5b378227f89a1ee2f48034efc22bcdba315de07adb217eVirustotal results 28.33% Quakbot
2023-05-18Ruaoyasa.jsjs d8ee25b9b238ffa9197d9bb3defe47e9a2720909109c315f32b38191a4c534afVirustotal results 25.42% 
2023-05-17Xydwbb.jsjs 3f883b067422272c3b10eea88505351741b599d103f66676cb75912106735cfdn/a 
2023-05-17Svlpcmyv.jsjs 828ab9b198ace6540bab66d12bff28bf5b11bb1258df06ae467240d2ff175f1bVirustotal results 24.56% 
2023-05-17Dgeewqx.jsjs b4bbe3eb6f77c745b1c296728e15c69c6b766df2aa51d6d745ce4e5fee415e06n/a 
2023-05-17Avhykl.jsjs aa29c7434c1bdbe52fd461a295dac0931392a0852902d70bd91693bedfc48375Virustotal results 31.03% 
2023-05-17Uprmik.jsjs c7018ff287088c076eb317d0b9402bc9dda25e832c0b205e91a3aeef7468bcd4Virustotal results 32.76% Quakbot
2023-05-17Bxefc.jsjs 49636b8d67746ef7da6e75b7b961332aa2ec681c92060c1648c4a9730e0abf7eVirustotal results 22.81% Quakbot
2023-05-17Egci.jsjs 3cc62e68f657fa870eabb640cd8e651d4ee69a242db9feadeecdbe6a0435ea99n/a Quakbot
2023-05-17Mgzmbed.jsjs 813efe88246132a445789b21b1536bd94263cd9a8c7623d7b96a9e5ac755d470n/a Quakbot
2023-05-17Griyt.jsjs d86bd24d259bd30a01c94fb535f0c0e3c8aba5557a6d5065e13de15d7b9ece75n/a Quakbot
2023-05-17Iwaym.jsjs 9bcb03f266dcce1657cc070f9b87ad562abe1836fb13710217a9866c5f35ddafn/a Quakbot
2023-05-17Btsbxta.jsjs 5e65f72351215bfb912a93dd2b37ce2963cfd0bb5e1c6986dc72844a3e8f190dn/a Quakbot
2023-05-17Zoaxlnmb.jsjs 8d30b51fa352affda93933bb361d1eeb949cf5edfe8b779953d992c4a38e0eb6n/a 
2023-05-17Qfaipu.jsjs 5c3e2f76eed1b2341c193b7bf3421d6e8604caa8623468e78eec2bfc0111a912n/a Quakbot
2023-05-17Ykzwp.jsjs 7707d6baca2f7024327a657b3c49cbfb2370ade804a6c8372cd8ae44348c952dn/a Quakbot
2023-05-16Rnbiapwo.jsjs 3118abe32ffddbcdb068998f903689286e4d6edc5377e1ba2cb6051953011128n/a 
2023-05-16Fafym.jsjs 35bd142bb2b84026537a1cc380433232f6caa8af0d13e3974beb34a654b0d8abn/a 
2023-05-16Nvbhpke.jsjs e654f87c9b111c082cdbfe922bbc14ba5d244cc59953bf3f7b077b274b57197an/a Quakbot
2023-05-16Vthess.jsjs 5368ef886a6426bea55e425b22700a1cd8e2ed3d71c195845c13e4ffb3132c3cn/a Quakbot