URLhaus Database

You are currently viewing the URLhaus database entry for https://allerorts.de/oa/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634771
URL: https://allerorts.de/oa/?1
URL Status:Offline
Host: allerorts.de
Date added:2023-05-16 21:52:23 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:53:55 UTC to abuse{at}space[dot]net)
Takedown time:2 days, 0 hours, 38 minutes Poor (down since 2023-05-18 22:32:22 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Owkthd.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Kprpa.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Olzxesk.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Vxaxhn.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Bhygqano.jsjs 388637405062bf8c291a2e1d2d23b2524d2fbb266b08618ba87d4eddd7d80db3n/a 
2023-05-18Qjio.jsjs 5e1581b1da5a05a5baee064cf15334c7199e5808fcb9b16decf62e6cb66940c5Virustotal results 32.20% Quakbot
2023-05-18Pbvctyz.jsjs a5f3d5a1dd9f57238b6a528792a0d6043f93289be9f4e2760c3549006c132bf8n/a Quakbot
2023-05-18Pdugxzv.jsjs 479435405ce11b58fbf16a8d7d4f3f1b2d8952718a2dd79f8c0e4ecb91176be8Virustotal results 32.20% Quakbot
2023-05-18Drxcprsp.jsjs 5002cf2a22a794f451347414eae921d359f14704e2fc3491ec70ae29266a6ea6Virustotal results 22.03% Quakbot
2023-05-18Eraprohk.jsjs 482b7c299dee3be25a3be3b76fb1498df5fc3e081d157b3734fa41fd8fbb5cccVirustotal results 27.12% Quakbot
2023-05-18Lhutxgqs.jsjs c28a0689fa744ad9aa6b9113d992a9fc9d303cf30f2b622975fb5e9a82ac02e6Virustotal results 27.12% Quakbot
2023-05-18Tklekui.jsjs 5b03a98354c24b442061c45caca4e261ba88fe1d68187bd4c44f84773d562a6dVirustotal results 22.64% Quakbot
2023-05-18Mfdw.jsjs 584680760762a6814ff84e38f5de401a9ba356c834f6302e03634c8883180fd4Virustotal results 24.14% 
2023-05-17Mlewzmh.jsjs cac584e2ff62f01ca51db682d0b6d32ff11123c3bc3b6a5e9794606ad51844fcn/a Quakbot
2023-05-17Amnzy.jsjs fc4e17680da39bbf2dfbf388da243c919927a825eca7d8de8a39d74be04968e9Virustotal results 31.03% Quakbot
2023-05-17Kysb.jsjs 55de6657c16f6c71d27bc0cb38580d689241943b653c659ae89fd4b63fdc279dn/a Quakbot
2023-05-17Ajgk.jsjs ca0444007c6c56cf207e9de8f069644d774953d9bc532784f55d5deebc62acbfVirustotal results 26.67% Quakbot
2023-05-17Mntn.jsjs 3cc62e68f657fa870eabb640cd8e651d4ee69a242db9feadeecdbe6a0435ea99n/a Quakbot
2023-05-17Lwjxc.jsjs 0857b5e40844024689620ed0e9d9fbef8b9b295f54e11fba7dd9693f59ce40fdn/a Quakbot
2023-05-17Ytpgpya.jsjs 9de5a133a987106b56f3ea9ab760d60b7d4bd41ed39055119f9eaa78dd36342dn/a Quakbot
2023-05-17Mymq.jsjs 89b46b49d9d3c23a2553ca4dc13a4889a915890d2e2bc03ac4bda1bb31e97282n/a Quakbot
2023-05-17Eipljjc.jsjs f0416a64edb85c92f41235372aa7915398908b7832770e63c5ddd154d0d98dcan/a Quakbot
2023-05-17Llqzf.jsjs bd83b0d1006a88a3433a32cbf4403b694b939b5ce1ea4f6fff4fd57420bb7fb4n/a Quakbot
2023-05-17Xumj.jsjs fefdeed49b86f4f987fdebf1d46103d615fa94371638dcc4a71ad22b383d2f51n/a Quakbot
2023-05-17Dspr.jsjs c9d93fbd5d057bd58d6e6556fd0f7e36442b3d4f9d8ccac1fbd5fc8d7bf05aban/a Quakbot
2023-05-17Pwfrfqjv.jsjs 780fad2dc6685834e7c7b7b1f9833b4459cb1a85fdcda38b7a72eb857beceb32n/a Quakbot
2023-05-16Ziarc.jsjs adf48ed5198cc7075f1d2f4524f8d0bd73264d9b9acdbf11da013693480e341en/a