URLhaus Database

You are currently viewing the URLhaus database entry for https://examexplorers.com/ra/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634530
URL: https://examexplorers.com/ra/?1
URL Status:Offline
Host: examexplorers.com
Date added:2023-05-16 19:10:19 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116752 created on 2023-05-16 19:11:03 UTC)
Takedown time:2 days, 1 hours, 59 minutes Poor (down since 2023-05-18 21:10:04 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Fqoppzn.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Cwhozb.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Xrcodl.jsjs a8a3e74636a81d4c390b35d9c7b6221871d0362f949cf846a91f11bb7c12aec7n/a 
2023-05-18Qphsae.jsjs e84b4920d25503f9505dfe8813b964551aa485cc176eb30dc5ac5e46dd5d56bbn/a Quakbot
2023-05-18Gekajp.jsjs 2ea57f7ed2c3148b87f87bed297e9f780f369a71667342ed01a88fc779a24eefVirustotal results 33.33% 
2023-05-18Aexg.jsjs def1eebe55f3bc428d1f39ef2f6c7d61a64a48dcc71389a348eefbb797e07653n/a 
2023-05-18Siozzu.jsjs cfc68b43d74cf7d5fd05920f53d7e80393899308fd60fbcd60c8582770294bc1Virustotal results 29.31% Quakbot
2023-05-18Ixlm.jsjs 7524d906b4d42ae7fd1e5e15cb503e8b54fdc1afa702a0b4e4c5f1d6f99edd1bVirustotal results 30.51% Quakbot
2023-05-18Mpovau.jsjs 7444a90ab199f093f90decb6774077ad55440f5d3ef1a757b95d2a4a639e60b3n/a 
2023-05-18Vyywnu.jsjs 1d57c903d9a9f7a6aafe34d3d44ced534b1878b64b93029c391c25c05c708094Virustotal results 24.14% Quakbot
2023-05-18Oujcr.jsjs ca3503a47ca92c4d7ffd385bf6501e373e48cae6b42c99b3a1d08f7478278c12n/a Quakbot
2023-05-18Pazep.jsjs f37d3c915b896922eed07327ecc8b944fcab1445d20c02c26c5aab8d91473b45Virustotal results 25.86%Quakbot
2023-05-17Ajdgtwk.jsjs 4422126c61949a9848ddc759de968eb699c5364973a271dc9aac631121591d13Virustotal results 27.12% Quakbot
2023-05-17Wyui.jsjs 1daf295e083f68a10f9527a63f47ad20185bc445825bbe8e6b92086996eeac2eVirustotal results 29.31% Quakbot
2023-05-17Ffvqnvhs.jsjs 0f979704b112aec8ec69c28f0075d45f2ed1aa14ddaa3effca523aaba13f0a6fVirustotal results 25.86% Quakbot
2023-05-17Kyuzttu.jsjs d25526dc27feb5e67f938d4b403a9dad1250e9bad80e8f4d66a22d696dacc328Virustotal results 32.20% 
2023-05-17Lucuwd.jsjs ee8f7825f5b87fbdb90f5bc8eff0cfadc358c64cfca2dcb37acfd398d5b2f201Virustotal results 26.00% Quakbot
2023-05-17Rumd.jsjs 74e7f951fe5dcd84fa5c570a1b2e27991662022a85a90f8f38cff80d462e8541n/a 
2023-05-17Jnvu.jsjs 3bc2c76bd30c4f67c56425ecd3201a7bd43655778be5fee4b7a2f72478c57d5fn/a Quakbot
2023-05-17Drcmege.jsjs fdf3976d9561bd12f769e871649c79b6d0fad08abe08c365525ca5f83035c369n/a Quakbot
2023-05-17Iopt.jsjs f8188e4762de8acb029ea9433c1832f762db5980a7cb754d45561d677a977c07n/a 
2023-05-17Aziu.jsjs 6fbe0b130cd5db869c5d015eacb25825a53ad82312b68da95d498639bd82bb68n/a Quakbot
2023-05-17Xtgnaum.jsjs f4cb74cc37bcf95127f582b6ee047a3b979728baa5c7d6f9e70ede3ffbd02bcbn/a Quakbot
2023-05-17Napyizei.jsjs fbc182f1e53d2b69f3a8b96ba19b572b0333a35e5319153c0b980c699292f33en/a Quakbot
2023-05-16Whxyt.jsjs 51f332a7f6743aa607b1825aca73b22897aa179bb343270d9cb966040ea5c708n/a Quakbot
2023-05-16Jdmagevr.jsjs 439f00d7111534616b9f77171fc6e3d7728e0e30249daa6ccd23e128c98442e0n/a Quakbot
2023-05-16Eqysq.jsjs ee9f477344335cdf491cf14b7b04ba8f8ee0392afb15551cbefe8a9be7816c12n/a Quakbot
2023-05-16Htuqpqei.jsjs a210ca6388d6a6a7ccd4266c11ac4838e19258203a4a06aa2cdf81d4408ee642n/a