URLhaus Database

You are currently viewing the URLhaus database entry for https://cointrasur.com/us/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634815
URL: https://cointrasur.com/us/?1
URL Status:Offline
Host: cointrasur.com
Date added:2023-05-16 21:53:22 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:54:35 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 0 hours, 12 minutes Poor (down since 2023-05-18 22:06:47 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bunyzh.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Pdcheqlz.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Zklzesz.jsjs c73bc000eff802a27a6201039ecd152b903a9371c58d12d1f4bef5fdc1b17ec7n/a 
2023-05-18Qric.jsjs 91f2349ddffafc85ec07721077d9d38a2ab0376beaf588950fe98bb16d3218efn/a Quakbot
2023-05-18Cyifrz.jsjs e8a4b575211295a78e536c4a374d5538f24470f6036d3a1e5ab52f149b6a5683n/a Quakbot
2023-05-18Wjinu.jsjs 494e69eca209ceb575b3ad74ff164605bc99c57a7621108280f95412b64e0becn/a Quakbot
2023-05-18Oawjaqju.jsjs ed3b42a466d5debc63224e8439d69996fd4f174cfcae800ac31dd8dcb69c921dVirustotal results 31.58% Quakbot
2023-05-18Wcnvzl.jsjs 2c402bf5ac40a8110c89bcf0f4ccd617ba22f8e8a6ca32d9949461c82540e48aVirustotal results 28.81% Quakbot
2023-05-18Bpiqssua.jsjs b65cfc5c1f188f590ab7d7d6a20d1ea638a086a9be61e3442b6ea9388fda3c0cn/a Quakbot
2023-05-18Oywyqouz.jsjs 69d10bf1c18cc7df540de106a1056c5af79f8b60f1ffae762d06532cc84375d8n/a Quakbot
2023-05-17Ybatf.jsjs 9d9924b0f0e33e1b74db34d25035395c2f29b1c29926ab16bfec2e29f30c8b81Virustotal results 27.12% Quakbot
2023-05-17Lzzkdrkq.jsjs c1064ed6356f294c6981938454ee3a3712e5e63930c1554a3c1602eacbd6554dn/a 
2023-05-17Thrgn.jsjs 92f5060e9693041974047a3d61fa5f29676b1451f9f09d9dcef17ecdde52367dVirustotal results 28.81% Quakbot
2023-05-17Whgnjy.jsjs a9c6050bc229b2d8d2b411d575194857f0f0b908185bcc15cd09d5c25f330867n/a Quakbot
2023-05-17Mcsuvu.jsjs 80a7de2f404881a80121516cbdf1869b885b6a138f992dc80f2e5e8337d47116n/a Quakbot
2023-05-17Zmmavax.jsjs 66b67f6722360b9477c07e41d8a832e907910dd99ba2523b724da1d856995396n/a Quakbot
2023-05-17Ftab.jsjs 14203ab6ebeaf17e09d6c5d576ee097f4087c38ee78c25b497b140d71f43ec39n/a Quakbot
2023-05-17Tfglkuea.jsjs 3bcd3adcfa799e38f52076f904c6b5f0940da5932c0dda106753bbefa84f910en/a Quakbot
2023-05-17Ezphrx.jsjs cf2b65ad6deea8453c92842edc0979e7cbec87c0375f8acce53c88709333a267n/a 
2023-05-16Hwvur.jsjs 2b2b43159b92a2241df4e4478a8e995ad2fc449c6bcd3dfd3d9b30eff8834826n/a 
2023-05-16Lbdr.jsjs 46e9ce8b8223e6a953e8e68573c10458f45e33bf6780deb70b5dde267310b7c9n/a