URLhaus Database

You are currently viewing the URLhaus database entry for https://pedaw77.com/iiuc/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634563
URL: https://pedaw77.com/iiuc/?1
URL Status:Offline
Host: pedaw77.com
Date added:2023-05-16 19:12:11 UTC
Last online:2023-05-18 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 07:04:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 1 hours, 48 minutes Poor (down since 2023-05-18 21:02:06 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Gkzgetu.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Vbivskqn.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Qxyoblv.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4n/a
2023-05-18Lofy.jsjs 98e6d003ebb7f44d703eec5d88bbf8da69b8ceb543fe2873a19bba3e9168c671n/a 
2023-05-18Pwhmwl.jsjs f517f6e7dd7c0f029a72fe25803ac2d5c54c7abcc8e576fbf95cbe6a87759540Virustotal results 28.81% Quakbot
2023-05-18Bnsqwvv.jsjs 3c55d89d269d20d6852bd0da433091d1fb247c736acddefdf23c414213857e73Virustotal results 31.03% Quakbot
2023-05-18Yprjjstd.jsjs 6f741f3bd19d3433e0618cd31b85f73aa09fb1dfe670c9e5a8e0ec01cf274495n/a Quakbot
2023-05-18Sbqd.jsjs 35a99626b0db91409ed1ac874964033c1490a20549ae611e95fa7f81dbd98d44n/a Quakbot
2023-05-18Lhduu.jsjs a4633a3bade267edfd4e6171fb238320ca7b8fc6ce56403954409c8af38c4ca5Virustotal results 27.12% 
2023-05-18Gtlcyxo.jsjs ecb53b7bd1821908e3358a50f35b5cc1aa92c43f7c190eaa7e0e473ca199dfa6n/a Quakbot
2023-05-18Ghyo.jsjs e3086e125c0def5547c4247942eaf8cdeb0e4e581562f9cef5e20b6978761c61Virustotal results 32.76% Quakbot
2023-05-17Yvupjs.jsjs 983c9fb0828b90c43eda528aaf767c2c7d4b71d59b86ad0d04461db11d91794bVirustotal results 30.51% 
2023-05-17Nzqnwtbo.jsjs 403516fd88c6e48a70d5ab2c1e966024e8e46c5403dcaa8dbb3b56774715cf30Virustotal results 25.86% Quakbot
2023-05-17Znby.jsjs 6f1a5f81c661643e1367ba7f42de50ede7d8841c0eb4bd7e13f5922b8a539766Virustotal results 29.31% Quakbot
2023-05-17Dstfas.jsjs ff4f21489a82d5367cbd581c4dde86dc238f869b950e07bf20f3928f7e6c7567n/a Quakbot
2023-05-17Muykmgk.jsjs 5cc7756639a24d5a8e14f7884507a76c1eb16843689035a0792202694705accan/a Quakbot
2023-05-17Mjjcubvs.jsjs 89ddd75a9d671f30070d8ed74468e507a72e5ca5699855296beb959dae2b71b3Virustotal results 11.86% Quakbot
2023-05-17Heitiu.jsjs f32e1256022a37c93429f2df0c87540583119ca913c038a1bce835786a3891a9n/a Quakbot
2023-05-17Yhcrn.jsjs 6f96d352707f837c3ea73cb343441bfab2aaf7c1588dc4a11d4c7a790781ad7dn/a Quakbot
2023-05-17Vceenc.jsjs 9d142bfbfc86a5f8b5de167c5a032cd5183152a9646ebfcbfe24f39f3f96f411n/a 
2023-05-17Bcre.jsjs 9629960ae29b54cf7b5e61b25d39a1df84582818bbcd0f223e657a7f6c86883fn/a Quakbot
2023-05-17Qihwvq.jsjs 8cc6d6bcee94f6319cd0e628be6e28dc4a072970cfb3329b22334dff661f75d6n/a 
2023-05-17Kvwjay.jsjs 49e1e668f9a01544ae84830feaa59000edc78264de16158c95fb1d96e01a6de5n/a Quakbot
2023-05-17Jwmlvl.jsjs 08709e026a13a02840bc54f95a667c204306c760b96c271fe00466832f3cd85dn/a Quakbot
2023-05-17Acji.jsjs ecc52d763c86f3b4704b82e72ca9640b168cf92ac6ac5da4f6344502d6dc54f9n/a Quakbot
2023-05-16Kwhr.jsjs ceb61de054f95ea1b95ca5f715fe09f893bd0b8e2ee34e48d0e43183edf0a72cn/a Quakbot
2023-05-16Eeoslz.jsjs 9c5593843b7f9ae39bea5157f0399e89749315278483efd1fccba94ffb908c7an/a Quakbot
2023-05-16Serlope.jsjs 8c09a2093112caf2d885e4b6b5f104e275ab431171988b36f097758572dcae41n/a Quakbot