URLhaus Database

You are currently viewing the URLhaus database entry for https://kschauhan.com/uq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634552
URL: https://kschauhan.com/uq/?1
URL Status:Offline
Host: kschauhan.com
Date added:2023-05-16 19:11:12 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:12:17 UTC to abuse{at}hetzner[dot]com)
Takedown time:2 days, 3 hours, 25 minutes Poor (down since 2023-05-18 22:38:02 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Jkjhmsm.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Vjidkzc.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Rumv.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Kyxajhyv.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fn/a 
2023-05-18Sjbsnb.jsjs 5c57b539392768e2e9e8490f11f6528d81875b4aae44e11319d0a94af50b1f00n/a Quakbot
2023-05-18Wtzrqss.jsjs bb62ccf9fa803df4844b790350de975a1f8ea136f9334e3563a5e8ecf4d9b601Virustotal results 25.42% 
2023-05-18Bzcsbz.jsjs 26bcf4ed38ca973b884b3322675bbd0b590533240961f9fd6272fa3e3aeba113Virustotal results 31.03% Quakbot
2023-05-18Jhmnaciq.jsjs bdc565778f51721f51d31d3a2fabe61b47bd3d921ace6ff98d7637b3cee485bcVirustotal results 22.41% Quakbot
2023-05-18Metppgkw.jsjs d6e5d8bb312aa607d892cd90a910040c5ff30ee3a76f41fd9c177f3c09b59f21n/a Quakbot
2023-05-18Mestgyk.jsjs e1210e09ca90b4d9b1cdd3dd947495e7f1666426a71a9032c997d1abcd93f686Virustotal results 27.12% Quakbot
2023-05-18Ueni.jsjs 783e0a457afb1237e0956e6ff847bfcdb49ee23036f51b4621b534f54d67112cn/a Quakbot
2023-05-18Jotyze.jsjs 6bb7a104fe821f46f0853eb826d375aefd2c29fca71738cc3494e5cd9ad1c40dVirustotal results 30.00% Quakbot
2023-05-17Mgglubek.jsjs f517f6e7dd7c0f029a72fe25803ac2d5c54c7abcc8e576fbf95cbe6a87759540Virustotal results 28.81% Quakbot
2023-05-17Dbskhuq.jsjs 1d2471f7acbab8882ea6f628275c501f0f81e0aeab5ee16537702bd849e8ba6bn/a Quakbot
2023-05-17Ghiiizg.jsjs 7a4ab56c0029ea06eceabbc4e8b9f005b37b97d1ea376ed3db95729269780e17n/a Quakbot
2023-05-17Lvatro.jsjs 447b96999dd079d4e5bbdefc464fbae41be6c1d6f55fa0d6dc0cf9db6f3490b2Virustotal results 23.73% Quakbot
2023-05-17Mkvmg.jsjs 5b2d175b18348c26ef8ad20f51fdeb4aa6ab4076aa57cc05caa3cc8772385077Virustotal results 25.86% 
2023-05-17Gtrd.jsjs 584680760762a6814ff84e38f5de401a9ba356c834f6302e03634c8883180fd4Virustotal results 24.14% 
2023-05-17Yrom.jsjs a357a8a9b62674cff6660b76659f4cd36ccd979d44937371bde57235d81c392en/a Quakbot
2023-05-17Kjsb.jsjs 6e988a313f3e3723e109adec17cbf1513010e50c972114a245ebf3ed743e84bdn/a Quakbot
2023-05-17Olgwmna.jsjs 48702114f4b421afad29b96dae599e71757280b16f9067a986260af0426b5a5en/a Quakbot
2023-05-17Bwzuhacx.jsjs bac35758be440400b5e2545da5f63ae3047bd9b3bd85405450f7f9d7fbb2e966n/a Quakbot
2023-05-17Rhba.jsjs fe3e27856a3581b169a48f1829ed18e736c6c239b384008359ae861886c77867n/a Quakbot
2023-05-17Ahgsvtbv.jsjs 3d5d48aebf3a636b3987b262ada8083286d39f4a5fff6df8d2375980b01f451dn/a Quakbot
2023-05-17Nryf.jsjs 11078bf220f61a59020211a4a030169429242e3f32c58a595873ec37850d3336n/a Quakbot
2023-05-17Ztvwjrmk.jsjs a12822611a4680481e5c05760bfb8eb183b03b75a98d7bd75447d8d5721a94b8n/a Quakbot
2023-05-17Jwee.jsjs 7dfd2461be4f3c8eadd95f5672c7202abe2a6f0cc859f51db66458ed258d3c29n/a Quakbot
2023-05-16Sknwieht.jsjs a1a53686e9ccd7f2dd22cd5d1c88fac0134e72126deb2a379b9e3285794454e3n/a Quakbot
2023-05-16Mxbw.jsjs 3062cefe85684204ff42eea28b7659754b86d294252786f769c76b8d3b2ed0b1n/a Quakbot