URLhaus Database

You are currently viewing the URLhaus database entry for https://tefcoglobal.com/ieot/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634615
URL: https://tefcoglobal.com/ieot/?1
URL Status:Offline
Host: tefcoglobal.com
Date added:2023-05-16 19:14:12 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:15:16 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 1 hours, 49 minutes Poor (down since 2023-05-18 21:05:04 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Mbkj.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Ibrl.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Nuya.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Uwhezn.jsjs 0693465b48ec60c86aa1dcfa43c4a9f59cebf49e24a05a9f662f1f8450401a94n/a 
2023-05-18Rxotu.jsjs 17c3055ce856c6ee8bbfdfa36ea81dedf3d495e3aa418145fea73358747d4cd0Virustotal results 25.86% 
2023-05-18Nttfvc.jsjs f093b882b8fd4a20a6b626c96af959ed31285d4cd57354e4cf7de124fb062b81Virustotal results 30.51% Quakbot
2023-05-18Pkfk.jsjs 185a635c927d918ae74aea58092eb9ecedc06bed0129605f9c210f1a3ad2d63dn/a Quakbot
2023-05-18Szfh.jsjs 6003ec795de91a5d5a9a9abb15e037b5f4dcd8cbf43bac5330005fdda61c603aVirustotal results 25.86% Quakbot
2023-05-18Xgiqjxq.jsjs 5fe1ce92222b0ef2d0fe599c26907689fbeb05acb3c14dcc9cd468d2db479a26n/a Quakbot
2023-05-18Xaibhxg.jsjs fd32fe1312ed075ac00d30123df24382ead0744d83a1a8787e5f0303d68f70caVirustotal results 30.51% Quakbot
2023-05-18Piyrbfon.jsjs 23c7e26757364f19557ee494d86b6dfc1c19e076aee18974a5443ce434459b22Virustotal results 23.73% Quakbot
2023-05-18Sjyienfv.jsjs f9a03e213a2bf36d23d4a6877af8261834b3049ed458410c5e8b4c6da00e2383Virustotal results 27.12% Quakbot
2023-05-17Hzxxs.jsjs b93e7c1a5d378e99de142cb47319276288120a8138977edf98875c43822f6d86Virustotal results 31.03% Quakbot
2023-05-17Zergt.jsjs 819e1677a9b83e3e2c5f43d5b2dc0f2f54147bd8257c067505fb818330efc68an/a 
2023-05-17Ocruqcyh.jsjs 0b5625e5e6c8ca17119f220fef0e5b08313f77e79294375e8b2c57d9bdc47ca9Virustotal results 25.00% 
2023-05-17Xwnu.jsjs f517f6e7dd7c0f029a72fe25803ac2d5c54c7abcc8e576fbf95cbe6a87759540n/a Quakbot
2023-05-17Gkatm.jsjs 7f5092d0b223ae713b6ead45d62c1c63d910a500fc960aeae16e1a1073355c86Virustotal results 25.42% 
2023-05-17Gpbru.jsjs ba77ea0ae3afe4582d390d1930a3792bde2ba411df7e3c05ae156306c5cd46e4n/a Quakbot
2023-05-17Jbaz.jsjs 7ef24e8dba41a6e1f91b0d04f772ccc6300b92293dcb30726bd5052c1e2ccca0n/a Quakbot
2023-05-17Bhjkx.jsjs 8e028afe5e530bff241456519d98c4afe35e4e8432ca6929cb4a327144ecb765n/a Quakbot
2023-05-17Mteduqvr.jsjs a4b9f5d60291e9a68cf1d1d5cb1da172ca56fe3c85eb912228ec2f4a5e3801een/a 
2023-05-17Gzsppes.jsjs c002dc54b5cfc8e5b389fee03b71c98a4231b3091326513c964f22c9c35b9be5n/a Quakbot
2023-05-17Vuzus.jsjs a26a068e8750903508465e322062ea992e924692ddce37dba3c8c5a2a888197dn/a Quakbot
2023-05-17Pgyjm.jsjs ca732357866e85969fd691fe45d867497db993076680031962351f612a9fad2an/a Quakbot
2023-05-17Hlixh.jsjs 1bb3708385f2dd557ffb8890444fb89dd4dccf0f01649687c65ec13324c7dd81n/a Quakbot
2023-05-17Nwnirisj.jsjs ad11cfa27a12d0eb117ebf5843e83edc37895133b14fca1ffcc052d80418185dn/a Quakbot
2023-05-17Wduzeyn.jsjs a88db9a944112b2b59357cbe9e4395e163c16f2f15022b1ca001a0376a330db9n/a Quakbot
2023-05-16Knuqht.jsjs 4318de62d20781b3dc18f436cd5944bbb069639d3d4f06b198ceba96e2d974e0n/a Quakbot
2023-05-16Wylgpdew.jsjs 91ddc1efe3c3fe3b1cc04d78994615fe39f9b8e53919b15dc51b8be17865c4a0n/a 
2023-05-16Srhlqbi.jsjs effafa59ece3d29a6afc0f789397bd3395071dfd41c1b1c0e380ad6ff6280aa1n/a Quakbot