URLhaus Database

You are currently viewing the URLhaus database entry for https://bizgrowsz.com/ca/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634805
URL: https://bizgrowsz.com/ca/?1
URL Status:Offline
Host: bizgrowsz.com
Date added:2023-05-16 21:53:20 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:54:29 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 32 minutes Poor (down since 2023-05-18 22:27:20 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Escags.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Mskialqm.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Pgww.jsjs 1804ac9fdf5cedae16eeafe669d17118823afa684ef79dcc67fd4c9c46e4c51dn/a 
2023-05-18Wrutmdab.jsjs 43f0a123b00abe19f1412b6fff2944e5bf4436a2ba20e3493ba9708ee5088c8bVirustotal results 24.14% Quakbot
2023-05-18Wefblgk.jsjs a18a3c0e37cfc92a00d139f4aebd7996690f4428dea318f028570bf9037d8aban/a 
2023-05-18Qqdrmjrt.jsjs 0f84fb63f382f7d5fa07382924a980e68a9af465c630f026b8dbfeb5a804c7ffVirustotal results 29.82% Quakbot
2023-05-18Adpvbrvf.jsjs 9898858b1809b1511e09fbef76498bfa2d39365eb70958ac81ba4a0263c6e209n/a Quakbot
2023-05-18Ciybghc.jsjs 1eaeb0800e5cf78a2590fb2ea6859c5f0bb66ad09354a079964ab9c7e6381781Virustotal results 32.20% Quakbot
2023-05-18Eytz.jsjs d72be2d3e9fcadaa237d2573ff95eacd51e973b70514465c8d57e7cd957769b2n/a Quakbot
2023-05-18Ipopzem.jsjs af020f4121ed33dba057c101c7d8fb714a2c96c883601c63acf7dc505818a5a6Virustotal results 27.12% Quakbot
2023-05-18Jfkkqao.jsjs 6d5e3d77360658771bba4d35e8dd94a77d30f33a7c30ab86b66e271b54d2a638Virustotal results 20.69% Quakbot
2023-05-17Wughzeb.jsjs 77a97bbae92dc7a7845ded72bd28a849a3c41c2912628816d93ff4b9a27ed45fVirustotal results 32.20% Quakbot
2023-05-17Gpvkc.jsjs 9f58336c0b0f6cde0a91dbee871cad45a315c5413863ef2b29affc9c949ee72dVirustotal results 32.20% Quakbot
2023-05-17Pkiqpi.jsjs 6f1a5f81c661643e1367ba7f42de50ede7d8841c0eb4bd7e13f5922b8a539766Virustotal results 29.31% Quakbot
2023-05-17Jtnthrt.jsjs 813efe88246132a445789b21b1536bd94263cd9a8c7623d7b96a9e5ac755d470Virustotal results 26.67% Quakbot
2023-05-17Kqxulj.jsjs 5c57b539392768e2e9e8490f11f6528d81875b4aae44e11319d0a94af50b1f00n/a Quakbot
2023-05-17Emhxc.jsjs 83a6906128b93fb8777e46c5a7c736321ce2cabe58ece643b53dd9884a1c6c77n/a Quakbot
2023-05-17Yjpeqkvz.jsjs 23fb378ba68beb5c6b1281c46215b56754ce9f89836c50f35b59615c2f79b455n/a Quakbot
2023-05-17Mqasst.jsjs 0107042269a76269dd71d3dc19e72a1759d421cbf33b9758b94f08c93f0989e6n/a 
2023-05-17Ggjewdss.jsjs fd5ae01998f71b19d2d7318db1a43473fef1dde375e03cc327b26ae6b4204f5fn/a 
2023-05-17Jxsrgq.jsjs 85069f18763293ddef2042db1ede74c08f302ea803868afe2c2ea9f78f623479n/a Quakbot
2023-05-17Yddok.jsjs d6a6af9e890e7189055a7e5030290c93ccaa8e47858856d5b12aa1e62def2f71n/a Quakbot
2023-05-17Bauxivi.jsjs c4966c1a07dde5c3965c411ccfbb5b7cd38a4ce2f8ad29d620ebd11c41819ae9n/a Quakbot
2023-05-17Wnyszag.jsjs cacbf80cd0c041d20032df37d4e1f46b31187b923bd05aae34b4dfdd8c2237f4n/a Quakbot
2023-05-17Jxyk.jsjs ef118fdf904b72e0f9ed768bb9e44e15b3d303b09d495c8074d058f3be1f7b21n/a Quakbot
2023-05-17Gotczr.jsjs 690eaf990e8a2101fe6b03fbb63f1e9aabb69d0173b64ae6e53a252018f9aeb5n/a Quakbot
2023-05-16Jshog.jsjs 531c0e5214eec99a2e81159cd4bfa1ef75764f15be010777e583a5faca1044f2n/a Quakbot