URLhaus Database

You are currently viewing the URLhaus database entry for https://pettitudes.net/aa/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634608
URL: https://pettitudes.net/aa/?1
URL Status:Offline
Host: pettitudes.net
Date added:2023-05-16 19:13:22 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:14:25 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 2 hours, 52 minutes Poor (down since 2023-05-18 22:07:02 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ptsp.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Zqor.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Lnfh.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Nccuz.jsjs 1c7174368b52616f53aade57808d0bdf77fb548d62af31e2661eeec7f98207d2n/a 
2023-05-18Sdonvnj.jsjs ba7f993248a05baa4fc8af51ce3e8f89889e817065c4b964cb37bfc088ae75d1n/a Quakbot
2023-05-18Ccnlgtdd.jsjs fa6d3526e896cb3ecf22f942020f813ff05b231a0755ca03e5588b547131c9a7Virustotal results 25.42% Quakbot
2023-05-18Vumwalc.jsjs deeae69c4717d775bf5fa189632028d3bea8fff66b068f15bb1c163430d3fb84Virustotal results 28.81% 
2023-05-18Cwei.jsjs d8227132d7300d02c5cf46a7c7c4ea76a6fcd10c516382dad0a8892266612025n/a Quakbot
2023-05-18Qvaxcacv.jsjs 9665c60390e6de64d398dc14f91957bbec2a396ca2c0ee79cde6f8ae0e2a585dn/a Quakbot
2023-05-18Xczs.jsjs 2a95cf3c1e69da726dd11f2d5621a546ce89b168fa1cab3506197a63de008d69Virustotal results 11.86% Quakbot
2023-05-18Pbvpt.jsjs 0ae16f66866567a01f4af47c0c7b2e49d1e54eba4e457b2de97f88c48016cedcVirustotal results 30.51% Quakbot
2023-05-17Pajfbl.jsjs f44e30ffb57afcf688c00896ca7384786ee3ede05210094b66c6d9d6c83675e9Virustotal results 18.52% Quakbot
2023-05-17Zbjptjjv.jsjs cc3f6d63f84cc1a94c7b2a3942b9e0df2af0f247cf2a81b2ba18f33ce401310dVirustotal results 27.12% Quakbot
2023-05-17Ccnm.jsjs 20336fdfef9d5684dd6055ff838104e334316b82122b0a12b809b529b1a66cefn/a Quakbot
2023-05-17Ivwfjup.jsjs 41004cb0d270673cab3af5cab1a87b9c6c88fd3a43f9a28494997c13652781c0Virustotal results 35.59% Quakbot
2023-05-17Ztrhre.jsjs ba4eb74cda0088a1269ede2dd12d974109f7b392ff522322070233d302cb3d01n/a Quakbot
2023-05-17Vnxvba.jsjs 2d4fa148f948ad83cb6ea9d45930d0384b699b8dad0de5e48214d4fcd895cad5Virustotal results 28.81% Quakbot
2023-05-17Gjoaxovz.jsjs b8080e6708e687876e70fb9577bdb538b92f84133aae0cd311c456094c77efb9n/a Quakbot
2023-05-17Rylgebtl.jsjs 46fb6e8a351d25945982316fb4534ca28403b5fa123c82fc214cc58d1636d849n/a Quakbot
2023-05-17Lycdxj.jsjs d72730afb622b8dad92060278eb8b6763215dcf6d7e210b56e75c13f05b189f6n/a Quakbot
2023-05-17Ooolpfuk.jsjs 48465c353c8b5edebe8052a629beca4b2ee7b1932c8a52848bcc39d93da41168n/a 
2023-05-17Uiituzu.jsjs 6958e25a789dab93800f0cc2165785a7e8dabfab9f28604eb48dcdd16e5a0f32n/a Quakbot
2023-05-17Zhhy.jsjs 641319ea92907fc5476a5151c40d118e1ae43ecb262fe7a04f1d8c6075c1b8ccn/a Quakbot
2023-05-17Eopkol.jsjs 9d916dbc81706f096291ff245fe9045980a42f0375dcb78603ea9dc3d015b8d1n/a Quakbot
2023-05-17Vwfj.jsjs dcb4a411017201dce463c0c650213dcaf20d00ebe216c042ca2a03fbfd03819an/a Quakbot
2023-05-16Tcsqfeuu.jsjs 010b96cc5361a1f03c87c47905714d4ab364a3be46501ebd80129324ad04a92an/a Quakbot
2023-05-16Rehp.jsjs f86aaaec63cba4ba0af3573dbd7ee5a82194c3f0b943afa44b846215a65768d5n/a 
2023-05-16Anouthja.jsjs c308cbb1f5217e84f4ee3157be092a83c600f68b0d1e0086a8352017944b86ben/a Quakbot