URLhaus Database

You are currently viewing the URLhaus database entry for https://cimbracapital.com/oo/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634789
URL: https://cimbracapital.com/oo/?1
URL Status:Offline
Host: cimbracapital.com
Date added:2023-05-16 21:53:16 UTC
Last online:2023-05-18 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116886 created on 2023-05-16 21:54:03 UTC)
Takedown time:1 day, 22 hours, 8 minutes Poor (down since 2023-05-18 20:02:37 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Hywlg.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Ttkrfeg.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Fvbxm.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Yibijcw.jsjs 0405a712d2c292f07fef11705b36010fa72e3ddc58b58f86edd1670d1296b1f2n/a 
2023-05-18Lqxt.jsjs bb62ccf9fa803df4844b790350de975a1f8ea136f9334e3563a5e8ecf4d9b601Virustotal results 25.42% 
2023-05-18Btkypy.jsjs 0d19b7d7e092df5355727bab9cbf454b5b17f90d5380ef6240d0cada7cb5a1c0Virustotal results 15.25% Quakbot
2023-05-18Smbxnppe.jsjs 6325a36db9c4fb5af943871bce9ae9c80002f6d9379e71cd94bdefe0342b14f5Virustotal results 32.20% Quakbot
2023-05-18Wgjaj.jsjs cf3f8bcfc47120345a6bf7e2b44265e2cb07dfc6d6aae1290d5552e5f6d2e1f7n/a Quakbot
2023-05-18Zwjflawd.jsjs 5c53fc6d6d29d37ae644bf3845ff851d6b03cd26eb5e411f93c26dcf018a4c35Virustotal results 27.12% Quakbot
2023-05-18Jgiiy.jsjs 71399d25c8497d7f81c87b8f5ec8d5071d8a62ac85ee254638bf8d24feccc5adn/a Quakbot
2023-05-18Ktrfzpy.jsjs fb5908d59b642acad4cc8e4b40c8003da06b37e422221c358758d820f2c0a53fVirustotal results 23.73% 
2023-05-18Npnyyg.jsjs b4b9340a057e2f27555df973e95af7d75b991cadbf943c5f48de2cbda1e3edcdVirustotal results 29.31% Quakbot
2023-05-18Qkvvrh.jsjs c66769c1beccde8a71bc20172ba3978dfa20fa8e27c21976b94c10327af6d4caVirustotal results 27.12% Quakbot
2023-05-17Rlqxik.jsjs 657ba945eb9c34584fcdaaaf316636af2fcddf21425ff248bf2de46d55dc8147n/a Quakbot
2023-05-17Fclm.jsjs fecdae98fff4b89aadb8c35ded8061bdaa126fc12f3fd482cbcecd53246c1c0an/a Quakbot
2023-05-17Rdntzun.jsjs 783e0a457afb1237e0956e6ff847bfcdb49ee23036f51b4621b534f54d67112cn/a Quakbot
2023-05-17Svqt.jsjs 17ee5a686914f6713574da4e30d7902af9bdfc03eb0173e1143cc97a4fa37b75Virustotal results 22.81% Quakbot
2023-05-17Uijbrolp.jsjs ff50e9d6bada1c148165cd94d8242cd7c0651692a508bbec763046c0ad17be90n/a Quakbot
2023-05-17Emyrmf.jsjs 98e65224d86b8f3b2be7f45d6b5bc6711e25eba8a298bf06d24ad94bfa8b2089n/a Quakbot
2023-05-17Iykhdy.jsjs deeae69c4717d775bf5fa189632028d3bea8fff66b068f15bb1c163430d3fb84n/a 
2023-05-17Tlmjlk.jsjs d5bbd027836baa611a3c9d5898119970c7c38d33faa287fafde6959dac06cf06n/a Quakbot
2023-05-17Elfqiixd.jsjs 8621b663e00f87f93a75d9acad9ef3f79ecf64400de36ffcf499f802209b7af9n/a 
2023-05-17Fjqhj.jsjs 7dcf9eaae2fed7ff9bb9e5b67730b1637587a62f9a7ec200f8ce79dc2fbd25edn/a Quakbot
2023-05-17Wqax.jsjs 7c76b5a4ed30ccfb56b3af046857452e9af4599faf0833ecb16ec9218e6abd84n/a Quakbot
2023-05-17Oqnet.jsjs 7fd2a226f5e70435934e52631800fdf8f3798714d666fcd929157af32b41f570n/a Quakbot
2023-05-17Wwkttsq.jsjs 44d97449db5d46e66de4330540191ac47177023631b0060869963191bbd0a690n/a Quakbot
2023-05-17Ofsqme.jsjs 8816919d3c9594f06e33ebcc505f6ec8310e1b6d674e8f373518dc08d36deaf4n/a Quakbot
2023-05-16Eyehdf.jsjs e91a15fa05e006d6ad109c5ce195423a7ea68858d32e4d9fcf1a57af1556d73cn/a Quakbot