URLhaus Database

You are currently viewing the URLhaus database entry for https://besocta.com/ce/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634748
URL: https://besocta.com/ce/?1
URL Status:Offline
Host: besocta.com
Date added:2023-05-16 21:52:14 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:53:36 UTC to abuse{at}hetzner[dot]com)
Takedown time:1 day, 23 hours, 10 minutes Poor (down since 2023-05-18 21:04:31 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Dsocfee.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Ycumltk.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Ucwrehqg.jsjs bc082bd1fdf447bf6d485a926de2aca127d0dad1a9d4d64cb5e4033f0cc34b1fn/a 
2023-05-18Ujbvtw.jsjs 6a2c26dc0efdfc1c4fdf83525f29de723f3f77f866558ce277756af920925c89Virustotal results 27.12% Quakbot
2023-05-18Atde.jsjs 4fd5f473b0f97c7dcf4a244234c780051bb0e3c316acbb18b7f959a6663c9454Virustotal results 22.41% 
2023-05-18Kpgxxcc.jsjs 0857b5e40844024689620ed0e9d9fbef8b9b295f54e11fba7dd9693f59ce40fdVirustotal results 27.12% Quakbot
2023-05-18Kljibgy.jsjs 0d025c1350cd713034b5b581118f5b7a71d0ba2551cc2321adbd286c8493fa25n/a Quakbot
2023-05-18Jdzavfcv.jsjs 80ab380263a5873a2a0e5bf0f6970a2c5a2f1bb6ced244bb881a685269c5d92cVirustotal results 15.25% Quakbot
2023-05-18Vmrjzjmr.jsjs 36c1b7c7a1b5c11ac465725f40b235b232adb02f122a1d9d3210656cacf4ee3fVirustotal results 25.42% Quakbot
2023-05-18Tswqclj.jsjs 34af4640c3591095a1562606faa096b2cab669c17859f8b99df4321999b17373Virustotal results 22.41% Quakbot
2023-05-18Ftrd.jsjs f0071ab8efac63f43a57e5ce10cebfd8f2d18f0b8df63002a484d4acdc24b4dfn/a Quakbot
2023-05-17Ufxml.jsjs 55958c9aef4b48e1d2648546d04249950dc900677dbaa6883bf95cc5db2df09aVirustotal results 23.73% Quakbot
2023-05-17Fphlkz.jsjs fc087bbfa79c07ccc635f8a6fd0b89dea00fce47f2c8fdd18e9a29c72d8a3bd0Virustotal results 25.42% Quakbot
2023-05-17Rnpqibpn.jsjs 7b501e67649c8608b6333e95e174a2d3db77d745651cf4142c43e79b0e1ed927n/a 
2023-05-17Oatea.jsjs b9db0988cfc1418354e6e55c54e7346c335a55a40661a6907d35143a9f8f8f8cn/a Quakbot
2023-05-17Wmnxmwyg.jsjs 399c7eece18438ba4f325cfc3863d0603d1237732a310fa2124a136ff2a335afn/a Quakbot
2023-05-17Urgurd.jsjs c98276273a209f91c3e1637785f0f3e59d5724b05ee395f9f32ae11ee5e8679cn/a Quakbot
2023-05-17Ngqwx.jsjs 80a39603b452c18848d8e79451133e805a170cdba19c7002e19b499be12944ean/a 
2023-05-17Fjnb.jsjs 85c8fafa66a79b49c167734ba1a3fed6f05b80d806fd9d28aefe0bf83cfc86ecn/a Quakbot
2023-05-17Cphw.jsjs 777ff602bfbfaa0e2e940eb67c5c1b3dde229b2d6b6c16b72f300c4e2ea44fbdn/a 
2023-05-17Iqsy.jsjs 2044cc3bd92825541a05fa8c38f7955123bec3b84bd7fed5ffdbb1a5411af8bbn/a 
2023-05-17Ktzhabmr.jsjs 789dffca1bd70f8b8c3f9c4cb7a27b80b25f5c4b06b66133508a72838fc34cafn/a Quakbot
2023-05-17Eipdbjd.jsjs 221dda471e732aacc07342517f6014799416f18215e39a5ce3a86975a4afb028n/a Quakbot
2023-05-17Maoezl.jsjs dd346e30aed3f1612a556c59d88e225166e4f7429110a61a985c8c9b1b4d609en/a Quakbot
2023-05-16Fcuuhnbx.jsjs 12e1f0b38f629d606bcf795778393e5e44e8f5bfe7e9570a6c4136294b42292bn/a Quakbot
2023-05-16Jnfs.jsjs b048e1be8fc0c668b3e19cd09168d3906f5ecaf1aab34ad3d386299a372ad470n/a Quakbot