URLhaus Database

You are currently viewing the URLhaus database entry for https://takagardenhill.com/il/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634632
URL: https://takagardenhill.com/il/?1
URL Status:Offline
Host: takagardenhill.com
Date added:2023-05-16 19:14:14 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:15:33 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 3 hours, 23 minutes Poor (down since 2023-05-18 22:39:13 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ywptmdzz.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Lynmmpox.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Sfdlxj.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Uzfjleog.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 29.09% 
2023-05-18Nrezewgg.jsjs 875bccb572b756073e35cf697abde47c18a8fc4156b093bd6d229ef766faed99Virustotal results 30.51% Quakbot
2023-05-18Whnma.jsjs 32710b418e9ddc449d0548590b62ac23975ad6efba53cc55cb1551326e182cb9Virustotal results 33.90% Quakbot
2023-05-18Pzwf.jsjs 973858251132d0779245a2e9dd301914a73702dadb9512759bce343a0fa1cb23n/a Quakbot
2023-05-18Vbvgpxmu.jsjs 798823d6f774c2380137f2e4d5c8a16ea4cec5e96284dfed0891528bdf512376Virustotal results 25.42% Quakbot
2023-05-18Zdshn.jsjs ed175d3585ab2d387e6c4a9420d8aa055d62ef6670fbe83a0f66d5bfaf943a92n/a Quakbot
2023-05-18Srorj.jsjs 62046b91a066c98a15aeba46b02ff8ae453c2d23d8e39a7e7eb2fb4d322464cfVirustotal results 27.59% Quakbot
2023-05-18Avuy.jsjs fb639f61394301ec51c3c82b270fa10118b12150f177db33a72560d80ad79f25n/a 
2023-05-18Ttgnqc.jsjs e33a486361f2b596983444fdfcab380bffa678c31788687e1d8fb8e9aed9f6b0Virustotal results 32.20% Quakbot
2023-05-17Btcehkup.jsjs 2c91bde6a534aee746616dd47460479f4813dd91fa6b608246e4cbd908aedf83n/a Quakbot
2023-05-17Zkxzdggv.jsjs b4a90889250c70642150c7b822ece35979290cb3664a5f778ccb8195b4c440ecVirustotal results 25.42% Quakbot
2023-05-17Sdldfdts.jsjs 33e5253fc3841fb30d4467ba7144f20b94bfb5714befb85aa32837899b33859bVirustotal results 27.12% Quakbot
2023-05-17Yjdce.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-17Bskyug.jsjs 3bc2c76bd30c4f67c56425ecd3201a7bd43655778be5fee4b7a2f72478c57d5fn/a Quakbot
2023-05-17Rmzroi.jsjs fcdd7c512aa91e5f6574a7c7ab77a118b9e1af5f2e3b502a5adb136508c4ba47n/a Quakbot
2023-05-17Arntpz.jsjs ba7f993248a05baa4fc8af51ce3e8f89889e817065c4b964cb37bfc088ae75d1n/a Quakbot
2023-05-17Djbwjlp.jsjs ce5e3c83c73f001007e94a00588eac1a8d0a4517468357c05d6c13cf35feef25n/a 
2023-05-17Orwdn.jsjs ac012803438be8d873d22197c99cce3c9ffee3d4a33d5165d276b60b3b1ec136n/a 
2023-05-17Dlym.jsjs 86b088ae4a876cc0c39302258bf5b0116a570b0aae6b20853fedff77bf6b82a4n/a Quakbot
2023-05-17Psjpv.jsjs 53645b63b91a0fbca8814edbfea422b2f75a56e1840b5011c96d1033ba147bb9n/a Quakbot
2023-05-17Xrfpz.jsjs b5fe95e441a2730436094241122bc0a3f7e8e5c1857c15b035aa1d9a5a4f2515n/a Quakbot
2023-05-17Dhhtohr.jsjs 8a181b931f546e95784cf376cb2b489d3409eebbca8b2c352b6b6168605c63dan/a 
2023-05-16Bozjvh.jsjs f575fe0b6cc98e6dad585f9a0b4e37d6cd4e89328ef691e5f11c86d9375c4200n/a Quakbot
2023-05-16Ttzt.jsjs 1f43a78e5f091334d85735b83546cd3dff1e4317259a25f72c97403f179f5943n/a Quakbot
2023-05-16Rzmqahf.jsjs da116da641a097a0872080efd9ca1f42e678bc91f21c029af0b8431e30084cf9n/a Quakbot