URLhaus Database

You are currently viewing the URLhaus database entry for https://batahandmadeshoes.com/ulrq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634744
URL: https://batahandmadeshoes.com/ulrq/?1
URL Status:Offline
Host: batahandmadeshoes.com
Date added:2023-05-16 21:52:14 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:53:31 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 8 minutes Poor (down since 2023-05-18 21:01:32 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xhts.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Vpgebyi.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Jhvtpdea.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 23.73% 
2023-05-18Iibotuqs.jsjs f37d3c915b896922eed07327ecc8b944fcab1445d20c02c26c5aab8d91473b45Virustotal results 25.86%Quakbot
2023-05-18Wdqvpbpl.jsjs fe38571546fce56178ef24eac652a6bdb02adb17817e8381824c1e1039b5f642n/a Quakbot
2023-05-18Vmkgzixs.jsjs 9fc5c95367df0d42df001590faddb4edf2e71a19e7159cb210d5525553462459Virustotal results 15.25% Quakbot
2023-05-18Lpel.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-18Rpfcls.jsjs a23cf11c2f986f5d2412a9c98d50dad0b0a02cd2dbbd6fdb1eb47c20cb7dd2bbn/a Quakbot
2023-05-18Yhvn.jsjs c56bdfe438e6261fa00e5e48e3e9896927886b959c2947db67582b4cf0f08e74Virustotal results 25.00% Quakbot
2023-05-18Tsfczbt.jsjs 07903a989b7e8631bdf7709c9f662e13388037ed84e2a225ce9707ff6d5679a7n/a Quakbot
2023-05-18Opjlymzc.jsjs bcf9e05bff1a4453dbe187a142eddb6857e41bbaf3869f7ddc598b6ddca0d276Virustotal results 26.32% 
2023-05-17Kasjs.jsjs 783e0a457afb1237e0956e6ff847bfcdb49ee23036f51b4621b534f54d67112cn/a Quakbot
2023-05-17Zenpers.jsjs 8ef706183443d30910cb1d411aa36e657e86119ff849b6a9edef4125b752bb92Virustotal results 28.07% Quakbot
2023-05-17Kbrfmkri.jsjs 1226b64c5cdc915647f5412f5ca66ffeb7ac2c6e7787e3f38195da88b68ca12en/a Quakbot
2023-05-17Jawqs.jsjs 1f26839da60e55672a1ff564cacf4050f50673ab46f7c13ece884b64e8db290en/a Quakbot
2023-05-17Ykokjf.jsjs da4bf3b68417dffef143d4e6c343ee8adb0fc59559ccca0c4ba48cd6e3e1e5f8Virustotal results 25.42% Quakbot
2023-05-17Pdcoadmj.jsjs 6325a36db9c4fb5af943871bce9ae9c80002f6d9379e71cd94bdefe0342b14f5n/a Quakbot
2023-05-17Ollv.jsjs 3b521273a1f49f0fb7c2f4ea15df405e5c77af2e36c653ca0e352ada89db0c6bn/a 
2023-05-17Lqrgpbk.jsjs 1376d6aa450344207b41d2bcc0b735e4d59b1488bd78237dd44400b02087f286n/a Quakbot
2023-05-17Clrk.jsjs 6e7b90cc3633a0151d8f68dff6260654ea9c3e7bdf64824e10950acd306e0670n/a Quakbot
2023-05-17Sopodktd.jsjs cad2684c055dd42b998216c12864ba9f75fef59184897fd3c785f0b7a4c4fe5dn/a Quakbot
2023-05-17Abqyph.jsjs bef482a668d52a30cdaabfed8c63ab529ff78191ada56dc40aab5eadac619f20n/a 
2023-05-17Xuriboyd.jsjs cff1aea3f20511c57e3c823520577c70d71c25b3dce98fbfc89153e24d48c6b9n/a Quakbot
2023-05-17Hsgkv.jsjs 34bcfcfdc82a53eed3aba04fee1ae96721c80fccd402065190e090c6e8706d17n/a Quakbot
2023-05-16Hscbsav.jsjs e4445b11568bc56bb7d954ed512299c13d2a212ac9e1a42544126836f166d02cn/a Quakbot
2023-05-16Vxgkm.jsjs 229a7282d28216a73bc240ef14c266b66002240d910b71200712ef62f32c64a2n/a