URLhaus Database

You are currently viewing the URLhaus database entry for https://cambodiatg.com/uq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634799
URL: https://cambodiatg.com/uq/?1
URL Status:Offline
Host: cambodiatg.com
Date added:2023-05-16 21:53:17 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116887 created on 2023-05-16 21:54:04 UTC)
Takedown time:1 day, 23 hours, 27 minutes Poor (down since 2023-05-18 21:21:39 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bezocmmv.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Yliyhaq.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Wktvaf.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Rmwbe.jsjs 3ccac9ae6859817e3376581245d0ebbb13ef5c3c54a5e552df027070530f8546n/a 
2023-05-18Nesmwfa.jsjs c419bc2833e48f8f26166ef911d3915be8fd0619ac6a0e0638813a4404df6979Virustotal results 25.42% 
2023-05-18Fmwou.jsjs c56be3ec9c7d01ede485ea9edabc332ef3aa01f6ab679c4eb6231e1db79db675Virustotal results 23.73% Quakbot
2023-05-18Tcyx.jsjs 6cc345a8ad3df8d8da07821f31095f9c217201e0065038c5bb7e15aae14a9035n/a 
2023-05-18Lgnmgjx.jsjs b896df419a5e1ac8fe67ede2b9594d6252e8dbf87ef64fd093ceacc52a84798fVirustotal results 24.14% Quakbot
2023-05-18Hjsmzugj.jsjs 9fc93269f064d50db15333e3dbcf15dccb35094dc51bedfc465ba99ce6a37953n/a Quakbot
2023-05-18Ptfyihh.jsjs c56bdfe438e6261fa00e5e48e3e9896927886b959c2947db67582b4cf0f08e74Virustotal results 25.00% Quakbot
2023-05-18Ycuauw.jsjs a5ad0d19dd6ae50f16dc5be1921c43a887aba5ab8dae04acbea417a5cd62d61cVirustotal results 26.32% Quakbot
2023-05-18Khkpy.jsjs 2936b6742f1d05f0f4625a1582b4bb5e44cf16340984eb0eaf2118709e5f7933Virustotal results 30.00% 
2023-05-17Jcxwan.jsjs ce9600cb7b98a80d9b5d95e0c7313cc05680b28366735b96104aa3fdf9ac0115Virustotal results 10.17% 
2023-05-17Zysnp.jsjs 20bd75aa446aa0b87c0d7042cd6119cf26dee2dedc5fe401477ada73a6c84e1eVirustotal results 22.81% Quakbot
2023-05-17Dltfh.jsjs a84a8c5338c73e889cff9d58c510657f8624b8deedf847eef71befacab5ed60eVirustotal results 20.00% Quakbot
2023-05-17Ivhzeubs.jsjs 35a99626b0db91409ed1ac874964033c1490a20549ae611e95fa7f81dbd98d44n/a Quakbot
2023-05-17Kfglyt.jsjs b96c9289fab9b7759ba3dd4ea2b84064aa296457443d10064d033d225609b55dVirustotal results 23.73% Quakbot
2023-05-17Unxivk.jsjs b9db0988cfc1418354e6e55c54e7346c335a55a40661a6907d35143a9f8f8f8cn/a Quakbot
2023-05-17Sjzfwjwd.jsjs 749721b74088db119de7bccbe5cea0c9486f42bb570461ff262c5ed324b4ca16n/a 
2023-05-17Vwlw.jsjs 788c284bbaa9f7739e4f51c770b30acc8cade2623299beccd8d7260c2bc1eb54n/a Quakbot
2023-05-17Txvqv.jsjs 107870ba2d7e8422cdcdca5a57961ab56efaad1e932768c6274adc8aac0136e8n/a 
2023-05-17Hhereh.jsjs 6ec566b1e95fb24a1b4322e90e7b0d81c764851c2de468984cb8ed0ecc8d4697n/a Quakbot
2023-05-17Ksnlv.jsjs 809ecac61435376dde8ea373411aa40faf0d6bc4169b9b67e7496621906f5550n/a Quakbot
2023-05-17Sukwwznz.jsjs e90f3561b76b551ab4b86c5a6755f640a123895b081a977bb8af370b20927538n/a Quakbot
2023-05-17Ddgbpx.jsjs 3a59b91d1fe6e408f6ce40a07bd1b4c50c9d20b2a269b4858bcc753c390093f8n/a Quakbot
2023-05-17Fgul.jsjs 00580d85734959c21102fe7a5b400069955e3be54589760735c3b70bb2c7858dn/a Quakbot
2023-05-16Uikymmhl.jsjs 9479b816f128fb9d9dbae584517c48d0dd81036ca77dc0933650535d576f89f4n/a