URLhaus Database

You are currently viewing the URLhaus database entry for https://sossurgical.de/tl/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634618
URL: https://sossurgical.de/tl/?1
URL Status:Offline
Host: sossurgical.de
Date added:2023-05-16 19:14:12 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:15:19 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 1 hours, 45 minutes Poor (down since 2023-05-18 21:00:34 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nhdigg.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Iivayv.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Nrtvse.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Tjrvy.jsjs b2364ea30109948d36f99aa0b62eed376d0a58a291c3e1079283cda17f161151n/a 
2023-05-18Fxcwg.jsjs 2ffe30857db286ab5839fb47499480fff446371b3c1f8df2d8dde6853266f088n/a Quakbot
2023-05-18Cfkxzzme.jsjs 9da26f54018ef7b69e7ca172d1ef9d1de643acee030e0b25c66a5f27867c8833Virustotal results 26.67% Quakbot
2023-05-18Xzsn.jsjs 6e98b0ad9b6fe81e7dde4a5e76cddfdc25b19695ca702e4faf95f45dfc5a65e4Virustotal results 11.86% 
2023-05-18Kpudcwep.jsjs 16fe8055701bf9e829e70c4811b31fc75aec4d03582697ab493fd530e84ac6cdn/a Quakbot
2023-05-18Pzlql.jsjs 6a2662394ca0402750ab97d8fe3a3010858b9dd07c373ce3b2579f8f0b13364eVirustotal results 27.59% Quakbot
2023-05-18Cjjnlxo.jsjs fb5908d59b642acad4cc8e4b40c8003da06b37e422221c358758d820f2c0a53fVirustotal results 23.73% 
2023-05-18Jtprs.jsjs 03652beb5abeb2e27fe43d5ddbecd035cbcb347a4e522a06b97f53e9c8f2c3a3Virustotal results 30.51% Quakbot
2023-05-18Rwwjcjfb.jsjs c7018ff287088c076eb317d0b9402bc9dda25e832c0b205e91a3aeef7468bcd4Virustotal results 33.90% Quakbot
2023-05-17Rpsmut.jsjs 4aa5d2a8e1f14eda407f7f6020bae48610ad7ecca61519bca8d513c840e454dfVirustotal results 24.56% Quakbot
2023-05-17Scoysu.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2Virustotal results 25.42% 
2023-05-17Nzaoquzw.jsjs 9aa3958dd376fcd792957165b53999bc05bdb411a0ea61e30b7787e1a7cdfbf0n/a Quakbot
2023-05-17Zufmnuyn.jsjs ce9600cb7b98a80d9b5d95e0c7313cc05680b28366735b96104aa3fdf9ac0115Virustotal results 10.17% 
2023-05-17Ysrfkox.jsjs a9c6050bc229b2d8d2b411d575194857f0f0b908185bcc15cd09d5c25f330867n/a Quakbot
2023-05-17Fblw.jsjs 0107042269a76269dd71d3dc19e72a1759d421cbf33b9758b94f08c93f0989e6n/a 
2023-05-17Kghfwv.jsjs a7559adb58fb8ca343a880d3a323c7307621cf7e95fee410922b0ee0d24d8bc7n/a Quakbot
2023-05-17Waojw.jsjs 8d541db8f29c1b94411ac352cb5df4a6dba57a9179273545514fe1afb3918df4n/a Quakbot
2023-05-17Dlskzgbp.jsjs e3b5388def1c03c5c0dc6f51879edb7822df324015957303866e8f8057e16df5n/a Quakbot
2023-05-17Qpfalpj.jsjs d206a72b10ce9523a6cbb4943e9747bc5d15fa22cbef6bb4d2424ae84a830770n/a Quakbot
2023-05-17Ykhz.jsjs 0272a1ed67b1bb584fcb0dbd592d83fa3a486ee839c01bbc0016bd513e56327fn/a 
2023-05-17Kpxhnjqq.jsjs 7f08a6d72910b42701ae28230e4460da202c1616ab59be28ecd2aa237f0d826an/a Quakbot
2023-05-17Gkeghvl.jsjs d426a0fcc038be9585eaf9734402e04f39cc83b3d7f57cab6315c32a72cbb4b1n/a 
2023-05-16Dezn.jsjs b3698bfcd8e1727bfe954285a28a4e6e281b25099a0da11439f63dd239c7a202n/a Quakbot
2023-05-16Lipzzjeb.jsjs 7bb4cae630c1024c309d55c7a244b817cfa0b9dc7b90bc93297450a5ae70c9a0n/a Quakbot
2023-05-16Wnnxgny.jsjs 38bf1b23f15cb752305a2163df6a01387237cabf67b370b3215905519e54b2b8n/a Quakbot
2023-05-16Tedmx.jsjs 69dc881e56014adefb1351ae92720d7dbaba3b0694779f0366a877f856dd79cdn/a Quakbot