URLhaus Database

You are currently viewing the URLhaus database entry for https://balochistantown.com/oeu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634766
URL: https://balochistantown.com/oeu/?1
URL Status:Offline
Host: balochistantown.com
Date added:2023-05-16 21:52:22 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:53:21 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 24 minutes Poor (down since 2023-05-18 21:18:07 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Axyfc.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Iltzkdkm.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Wwkruqkg.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Ytqfmtnk.jsjs b242355381337a8c4aa62d167d37ff1336a1949fe11b5e19cbc90499b105db68n/a 
2023-05-18Regymt.jsjs 91f2349ddffafc85ec07721077d9d38a2ab0376beaf588950fe98bb16d3218efn/a Quakbot
2023-05-18Gasjw.jsjs a22b66a10925ee0bc864c2b920e30792c9c23d171ffe1d926a43d0403fa0f1c5n/a Quakbot
2023-05-18Swibith.jsjs ed175d3585ab2d387e6c4a9420d8aa055d62ef6670fbe83a0f66d5bfaf943a92n/a Quakbot
2023-05-18Bprms.jsjs f7141b5e0f8768e0c1d39b6da886c311b1ba7a4a1db8d4efe2c936270bc2f0c8Virustotal results 27.12% 
2023-05-18Mckaft.jsjs 874c90fd9f5dbc042d5e87dee75b68570376e628600a8d08dc1083545283052eVirustotal results 27.27% Quakbot
2023-05-18Debflvha.jsjs a1353f7898cc49901d6c5dc01063b60be173f0ab2378d18348e3b766cd3a9913Virustotal results 25.42% Quakbot
2023-05-18Oletay.jsjs cbc57ebccb343515692b47782246ac3ce19ae8ae335ddc9895810261d11cb663Virustotal results 16.95% Quakbot
2023-05-18Dojh.jsjs 9162c26ac66cb673664c91b6a22e788a008db7c2bd2b4a9b7788a47fe85f33eeVirustotal results 28.57% Quakbot
2023-05-17Eninmr.jsjs 229271acfd7face73c4919f8ae74ec7e9e3d276810827e045c7ee12baf2e75bfVirustotal results 30.51% 
2023-05-17Kyxjmumu.jsjs a18a3c0e37cfc92a00d139f4aebd7996690f4428dea318f028570bf9037d8aban/a 
2023-05-17Ucobv.jsjs e50886cba40b1a43e2a678f24566fd07c951a78a554670ec3b2f25a3866d0d57Virustotal results 22.41% Quakbot
2023-05-17Igbuddw.jsjs ad227c276250c72ebaf4c13e5d960347009d0762b8c2e696a35b36232e0eeff0Virustotal results 27.12% Quakbot
2023-05-17Itdypmer.jsjs 31bfb0e9f32a6891aa3b4bb9c1caeefec664295de95b74eccecf9eb67a2b84cbn/a Quakbot
2023-05-17Pbagn.jsjs b896df419a5e1ac8fe67ede2b9594d6252e8dbf87ef64fd093ceacc52a84798fn/a Quakbot
2023-05-17Hyahf.jsjs a4633a3bade267edfd4e6171fb238320ca7b8fc6ce56403954409c8af38c4ca5n/a 
2023-05-17Aoeovzvy.jsjs fa53df7429ce0c95eb35c49ab5540f5b6bcba5484101689a2b1e021dba8182d1n/a 
2023-05-17Xmdgb.jsjs 16a10f369bfb4bb92e465ef5a17ae72546d46ed769f0f011fb3adb45245a4012n/a Quakbot
2023-05-17Rzpmvx.jsjs 017a8af42416a203946b4ca4c72f188dbc64e4c75b8b5fefb5c2e63937fccc71n/a 
2023-05-17Bhgvovi.jsjs ce029aa1b779be7285f4c93c8b994fece4efbad35da8b7e6b6cdb38c7422267dn/a Quakbot
2023-05-17Wtuythmt.jsjs c3ac5cf470db77c7e00d803593bce44f217a3921cd1c3098f8a937abdd2c5ff0n/a Quakbot
2023-05-17Jlgs.jsjs 73001c7ebcec14b6cf353f20ddb74b08126dff6cdf04384d8b5539748c462556n/a Quakbot
2023-05-17Lqjjey.jsjs a6d4258c6c7ce253fe11bb3955d432ba47d2d0cab5e3b6380f633db281456ddcn/a Quakbot
2023-05-16Fcnu.jsjs 0efd597408d657b2fb9b11581310d715a0d78ce0109f18c973958c05d4042868n/a Quakbot
2023-05-16Drum.jsjs 9eca3bad2c6268dc191971895af6318aa55e8d8e75b14364b20b001881d77224n/a Quakbot