URLhaus Database

You are currently viewing the URLhaus database entry for https://ar-albania.com/epso/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634770
URL: https://ar-albania.com/epso/?1
URL Status:Offline
Host: ar-albania.com
Date added:2023-05-16 21:52:23 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:53:35 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 23 hours, 49 minutes Poor (down since 2023-05-18 21:42:42 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Pwhdkw.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Ljmn.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Mfwynqn.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Bkhqcj.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Fkjmfqct.jsjs 92541d594f60bdb46e24073e3720e0deb32a8bb5a4409a44b650b790dbeda309n/a Quakbot
2023-05-18Wyjvqxb.jsjs ceb34fba0cd428a9dffee10f6b9c5857bfe8e363974adecbd1c42b994a5bb36cVirustotal results 27.12% Quakbot
2023-05-18Crstp.jsjs 7217ae2adc382459d109d0ca1135074318d85578de92f3c231dd520402b6d647Virustotal results 27.12% Quakbot
2023-05-18Flyz.jsjs 6a2c26dc0efdfc1c4fdf83525f29de723f3f77f866558ce277756af920925c89Virustotal results 27.12% Quakbot
2023-05-18Pbcntkn.jsjs 2a893ca454c8da14c3b8682420a27dee70132a6fc3dc8975c4ff49a12a7c64d6Virustotal results 27.12% 
2023-05-18Usvxmtbl.jsjs d953d8ab979233a6b29a964f031086bd74ed7eb684d99d10f5a881778f4d13b2Virustotal results 27.12% Quakbot
2023-05-18Geigik.jsjs cca9ae0f45d9d362a7e18d9f86ed7a18a1340c3f3d4811c7a2ddc658408bd496n/a 
2023-05-18Kaliboo.jsjs 5ca41989b791311510cc85281b20f28cd72d2554b2a862f47d9a9ac5ba9a70f9Virustotal results 25.00% Quakbot
2023-05-18Oovisas.jsjs a5f0035e2f6ab21d643775a304ea994d963bc0ad712a5ae1a9ebb1a5298f7adbn/a 
2023-05-17Ikiitfbf.jsjs 7fc4905fb7d4a1e1c931e869fdfaabceabbdbf242ca9e35ff7178f74e6f7b207Virustotal results 25.42% Quakbot
2023-05-17Xpkq.jsjs 6b01b5522683c655f6e33fc4ecfa2ef55bae886a543ba306b61dd976a892fe96n/a 
2023-05-17Pffd.jsjs 7b501e67649c8608b6333e95e174a2d3db77d745651cf4142c43e79b0e1ed927n/a 
2023-05-17Clppjke.jsjs ca0444007c6c56cf207e9de8f069644d774953d9bc532784f55d5deebc62acbfVirustotal results 26.67% Quakbot
2023-05-17Sdtq.jsjs f7bc14c8c137444d5d046f1c1304ca9eb96509ce61adeffaa967dc07f21c17d7n/a Quakbot
2023-05-17Dvgl.jsjs 73abfbef5c169e5239c78d4c04f3d18f7f72490c2ca0cbbb33d92cac9675dd16Virustotal results 27.12%Quakbot
2023-05-17Bnzg.jsjs ad9d5d545cd208607067a384f752e68873813a4863a25840901805e6778a5f43n/a 
2023-05-17Yvvluc.jsjs f46b2da24715f6dea1b264c3f7d4527fff065777e30e9fa993f4bd3e58d584e1n/a Quakbot
2023-05-17Rkrmi.jsjs 27f6e15325f38d04dbcb600a47523d66fbdb6968adba3b9809e00cf058ea8ca0n/a Quakbot
2023-05-17Jafozlrj.jsjs d1ad673b2644bf5fc3eea0dfa8c517d0bc789f2a14720d670e0fc6773cd7e026n/a Quakbot
2023-05-17Xtbrcmd.jsjs 4b3ef3d6ac1c23d08b347007985000cf59ae87a495613e0d2c5486f6df4bbbcen/a 
2023-05-17Xofycyc.jsjs b81e69c340f725bde3eb18e81331ca48da3e403ae40b7e27c258d8829bb67f60n/a Quakbot
2023-05-17Jqws.jsjs ce13c3c052ea0abd55a0e03c7ad6de5799115c126763f04f35a3df0319a72a51n/a Quakbot
2023-05-16Hgqelm.jsjs d27aaa7a78748d6a427c69c22089bdbf67febaa3f43795e1e882814f84a458aan/a Quakbot
2023-05-16Bqrjxema.jsjs 7dfbfd8572be98ecb6ef0d649f663d297628a7c7fa80fe273abdb5eaf14c9315n/a Quakbot