URLhaus Database

You are currently viewing the URLhaus database entry for https://udaypharmacycollege.org/aae/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634637
URL: https://udaypharmacycollege.org/aae/?1
URL Status:Offline
Host: udaypharmacycollege.org
Date added:2023-05-16 19:14:15 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116767 created on 2023-05-16 19:15:05 UTC)
Takedown time:2 days, 3 hours, 38 minutes Poor (down since 2023-05-18 22:53:55 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Sjwq.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Plcq.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Jssz.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Mnns.jsjs 7e6136edc7d78868b7fc550f4adb468e5207574401cc70a8e5e7a24752db04ben/a 
2023-05-18Toupngz.jsjs 7e14e82b93e7a51daf3ab028772a41e20e60a31cc1a90985cf3598206b08805cVirustotal results 25.45% 
2023-05-18Roiv.jsjs c6712a15900f7986ac9ad350dec34f50284b50e708bdeb42e320d99659f8d46fn/a Quakbot
2023-05-18Lsriaj.jsjs 34bf72fbc4370971ff89c72391aca2a8a5b37aac3f1cbb8f2ab5480a3df6ae0fVirustotal results 32.20% Quakbot
2023-05-18Qgnqapt.jsjs f0071ab8efac63f43a57e5ce10cebfd8f2d18f0b8df63002a484d4acdc24b4dfn/a Quakbot
2023-05-18Vzvmx.jsjs 66a44d6ecc0bff8550c4f8fd93b40851e019bac6297339dd180d268ed9bba451n/a 
2023-05-18Hylltgeb.jsjs 043c810fd7d77672928841fc44891531ce536c6b4cfb9a4e54529c20b36eecd2Virustotal results 30.51% 
2023-05-18Qsghqji.jsjs f7141b5e0f8768e0c1d39b6da886c311b1ba7a4a1db8d4efe2c936270bc2f0c8Virustotal results 27.12% 
2023-05-18Wwafwp.jsjs 1f3d3d34fcd02bfbd9eba7becc4eb01342dffb209af4971f9df25374411cd1a7Virustotal results 28.81% Quakbot
2023-05-17Ngad.jsjs 0d025c1350cd713034b5b581118f5b7a71d0ba2551cc2321adbd286c8493fa25n/a Quakbot
2023-05-17Wvppb.jsjs 4cfd3cea6e5aacf340993648b46bbd6628953021cc5148be665b68de39755e98Virustotal results 27.12% 
2023-05-17Qcgbs.jsjs d7efcadce017eaba7ee055cac3f1fb9842bd54107fb46729f546ede523c09e5an/a Quakbot
2023-05-17Waqhyrfr.jsjs a5f3d5a1dd9f57238b6a528792a0d6043f93289be9f4e2760c3549006c132bf8n/a Quakbot
2023-05-17Lkrkcrpa.jsjs 1539b3e778af6f644e932c0910705fec144fe2bbef2f8df241b0d4bb821d0fc5n/a 
2023-05-17Pckayjno.jsjs 812cc57a966264823ac9c3e7a2ec885f1ade0a4a304ac4ef12554bbf9328338aVirustotal results 25.42% Quakbot
2023-05-17Bzqmdaoh.jsjs 9f58336c0b0f6cde0a91dbee871cad45a315c5413863ef2b29affc9c949ee72dn/a Quakbot
2023-05-17Dpdoqjsj.jsjs fb639f61394301ec51c3c82b270fa10118b12150f177db33a72560d80ad79f25n/a 
2023-05-17Ickwe.jsjs b0d3a537202f8cfedbae2c5862703b391b71471ff8d5bfef300595a077d78ee7n/a 
2023-05-17Ownmihe.jsjs 3270f1db966233d240500e3d8da83ebefde43815f48c3e197946764688719aaan/a Quakbot
2023-05-17Stqcg.jsjs 4a5fbbc7d41cd55142c9d928df34cf0eb3379bb61c40e8cd8f8468a2cf21c1adn/a Quakbot
2023-05-17Opanvj.jsjs ea9cfd0efcf121a4b1cc7aabdb1adc0688f655bd02b960ad6c66578d24c70942n/a 
2023-05-17Ugdtznp.jsjs bfaf63f3ac5321ea711675ff3c6fbdc3119eafd4ca54c730f21dc8165338934en/a Quakbot
2023-05-17Xvjpqvj.jsjs 0eb0ee5b1331f7e384085c7222ecac6866fa9933deeb922bc7adb9980defe5efn/a Quakbot
2023-05-17Nvdo.jsjs edc1b8376a8ea92f0244de0d31d762c2a8da2f12d4beed2125a5537fdf9c89f6n/a Quakbot
2023-05-16Yqtzn.jsjs cb582bd53a8277e40b13e767e6bcb4f25fb111b4e02eb7f824df4d6a0e63943cn/a Quakbot
2023-05-16Daql.jsjs e01f75a5e7df1110135d5ae909ce506b4b47c8f7c04eae94ecca849833af346an/a Quakbot
2023-05-16Xpoujsau.jsjs 50cf9c92b2645111b075b6506ee9b9313fda4807e030e82994c4dcbe2844ccccn/a