URLhaus Database

You are currently viewing the URLhaus database entry for https://udaypharmacycollege.org/cup/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634638
URL: https://udaypharmacycollege.org/cup/?1
URL Status:Offline
Host: udaypharmacycollege.org
Date added:2023-05-16 19:14:15 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116768 created on 2023-05-16 19:15:07 UTC)
Takedown time:2 days, 2 hours, 17 minutes Poor (down since 2023-05-18 21:32:47 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Afmqesj.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Mkhq.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Gdhvtar.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Svxxii.jsjs 1326caff6165a1b131e23ab928b8aa780b095ae5c2f496f7144b0d3059a8e5abn/a 
2023-05-18Ohwlenm.jsjs 9ac768cf3025869132bdb78aad3f4505cd8dd7e5ddc218e64d6645ba8db5e4f4n/a GuLoader
2023-05-18Ucpsv.jsjs 55de6657c16f6c71d27bc0cb38580d689241943b653c659ae89fd4b63fdc279dn/a Quakbot
2023-05-18Xspckojl.jsjs 8cb9812b4c0409176b2f0770497520692218130496cf0a2a363b4606ce28f506n/a Quakbot
2023-05-18Vlczll.jsjs bc08bfae3a441cb9485634aeda5f5ae4cbbe5e36cd98ce7b2812cd62ed4e5034Virustotal results 25.42% 
2023-05-18Xgvymvep.jsjs 9da26f54018ef7b69e7ca172d1ef9d1de643acee030e0b25c66a5f27867c8833Virustotal results 26.67% Quakbot
2023-05-18Qfossyc.jsjs 17c3055ce856c6ee8bbfdfa36ea81dedf3d495e3aa418145fea73358747d4cd0Virustotal results 25.86% 
2023-05-18Ienkcrsg.jsjs 148425d44762a381cbc5cf7c9e0e7fb44d71f7162439e78b219929274f34d19fVirustotal results 25.86% Quakbot
2023-05-18Lqgiwl.jsjs e83bd9c4b21fcd0dac063c512259b7310762d0f7b923cba778206403e5314398n/a Quakbot
2023-05-18Qsmb.jsjs f16b3c48ca1ba324e53c48a72c3bc53329423b16779e1cd1d0d40447f39cfefaVirustotal results 16.95% Quakbot
2023-05-17Tomqczo.jsjs b19665dd5f7dbec102ef5c751b9f86dbe37003d54eb666e3be898351373a0486n/a Quakbot
2023-05-17Toeps.jsjs 559259d8417125f8b762aadbb8a48b34058c7ee430dbe672ad8c7bc3fb919103Virustotal results 25.42% Quakbot
2023-05-17Bgkjeyc.jsjs b267e2261f79527d447d6a639751fcabcf68f9640e62a3c3106b4f750cb07b66Virustotal results 32.76% Quakbot
2023-05-17Gkqawvh.jsjs 61ef6ef0f9ddc3b6d4b8201a85d35c7ce79058c5ccbb5ccb51e68f15898a3bf9n/a Quakbot
2023-05-17Ycjdy.jsjs 4de2124d922958dc3b36346c1906578b79f12a6388ef771a7f8503c21e30af78n/a Quakbot
2023-05-17Pkxixs.jsjs 269dec903e55df2babe1cb8bb498ac7fe56d2a079cdf89c2d5c354b7a8fa1250n/a Quakbot
2023-05-17Qihjr.jsjs 13fdfdaf64e65db124eea99e68a7cc977a3be435abde97c21a1108bf0aaa4f21n/a Quakbot
2023-05-17Koxz.jsjs b16cbff4726c4eb38459d4189d7a10123681940882ddb3c0aa651c049ff0b935n/a Quakbot
2023-05-17Evfgsj.jsjs bb0719076e594735c4a98c44ec92c7e40799cac555e2ecb5ab90547939815f3bn/a Quakbot
2023-05-17Rnjsdiw.jsjs 9d3beab72b4d2bd53b844483febcbd7defbb1497873fc0a815e5d31dfc16ac64n/a Quakbot
2023-05-17Wkshfg.jsjs 8a05f9a96be252f495b1128b186ba1f26ddf6b131c092227f722cecd24034f02n/a Quakbot
2023-05-17Qefpaxsb.jsjs 1ed4d713c904ab17fa9bf26952d037da8aaf1abec69f716428dcf9e88a77b8c0n/a Quakbot
2023-05-17Dqffwpo.jsjs 28c67d4db5ff23ea9ad2ecd10670c284c16876749d5e0ebb68a47b9eea979041n/a 
2023-05-17Kyzzz.jsjs f77e090ec28a27d4c9bfe02c37f0878b09bec3575a6b3f434245d2c6caa64bb9n/a Quakbot
2023-05-16Yeblv.jsjs de8d01e395ed8b73760f076b965d070e25be5b37aa51880fda881b5af3ddcb23n/a Quakbot
2023-05-16Rsxfl.jsjs 47391580e8199d30204422f5e41b24dec7ac20706a8b74513d6113d21d5d883fn/a Quakbot
2023-05-16Drns.jsjs 520e3109e8bcd7199b28ddccc338d5487458b476e89fb2321e27c43f580d85fbn/a Quakbot