URLhaus Database

You are currently viewing the URLhaus database entry for https://eliteservicesgarageopeners.com/umms/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634828
URL: https://eliteservicesgarageopeners.com/umms/?1
URL Status:Offline
Host: eliteservicesgarageopeners.com
Date added:2023-05-16 21:54:13 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:24 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 0 hours, 53 minutes Poor (down since 2023-05-18 22:49:18 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qbmekkw.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Caasny.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Vvzwuukd.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Ruwmhq.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 29.09% 
2023-05-18Pkokfs.jsjs 7c13bc2d2d42fdea47cb32e74e359fa9939073a81098e801e04a6daaee5e9ff3n/a Quakbot
2023-05-18Pnfx.jsjs 47831ca3235332c96696b1add7425b7dcb044b9de06934992957a5e00cb4dadcVirustotal results 25.42% Quakbot
2023-05-18Blxfluub.jsjs 9079446bd4c7bd26e207e6897766f15bb65c2e6bd4802d253ec23072dff72e4fVirustotal results 27.12% 
2023-05-18Iips.jsjs ca42f27ebd7d4d5472c9652e26b5cd7d9f089e838ea85a8ac5f1c51b37e83e30n/a Quakbot
2023-05-18Urea.jsjs 2148fe2b647b8aa1006957e65de07d42e631ced18a21aa3d1aef1ad5d22ffae2Virustotal results 29.82% Quakbot
2023-05-18Gxjvcjix.jsjs 91bf97c2e5d25bf79ff22ef99cccd3bdb7aab412d34521e172610b16562203d8n/a Quakbot
2023-05-18Vltrpsxe.jsjs 8c4f0c45a34f4cd509c3354346e0db29fbbe4bd099e2b67de6abc88dde35081aVirustotal results 25.00% 
2023-05-18Dqgzpy.jsjs 819c3375d47e95f26e1466039e2ff5a096837d0761bed7564c2366b094c8895bn/a 
2023-05-17Txzuwgon.jsjs b726185bac5c9502b0014a711f793d0559b2d0afcaf5cc376d063cb315412020Virustotal results 30.51% Quakbot
2023-05-17Oayja.jsjs 5b903308829f5c7410c0e53ec748a05a9e2205f4400bf2941199cf2223c0e1f7n/a Quakbot
2023-05-17Asdudnq.jsjs 2971e245d875fcb96bbbbcff59e1a34e0490ae85f5e8abd688b28772bca0b30fVirustotal results 34.48% Quakbot
2023-05-17Gidh.jsjs 5284d5807da5986ffb17fdd9761066974cb34030eb5067e7f9a65e48b32f37e8n/a GuLoader
2023-05-17Kkfgjgi.jsjs 148425d44762a381cbc5cf7c9e0e7fb44d71f7162439e78b219929274f34d19fVirustotal results 25.86% Quakbot
2023-05-17Atsnsew.jsjs f6bf73aa768753f4379e2df6f0094dda46beb48b879c76c983896434f67c0ab0n/a 
2023-05-17Axkvfh.jsjs 88f6a8cb20802cddd090c331d20f9642aed6deeda17214154bc2017f911d61c3Virustotal results 21.15% Quakbot
2023-05-17Rdzofyr.jsjs 32805d4a1cf5298234803410351824aacdf3ae591f390289a3ae325ad6e77e1en/a Quakbot
2023-05-17Ddmyijmk.jsjs 0f9c2c9390c30e036304c0e6ad12428e40ac45213ce31f2802ee71dcaed477bcn/a Quakbot
2023-05-17Shssnkpa.jsjs a7a2f0af49d4b6ddfeb2b765c80d44e4fd545ecffd04d097ebd60516f2ed183en/a Quakbot
2023-05-17Bgvksjs.jsjs 617df8c72f64b3c29beb9450eb4f002b85d8b0ef9fcd2cb469f530548bd7374en/a Quakbot
2023-05-17Gyoiuik.jsjs 6d35a3423113356868c864f5908bdc631b730d09484578f7b684f5fbdb9bac5en/a Quakbot
2023-05-17Fsarbcz.jsjs 1878036e196033e2f308d200b2c0731d9546a9cc19bdcc198b3547e863f3ae55n/a Quakbot
2023-05-17Rxwodoi.jsjs 936111c1cbfe94f283d4b17e4b81640a7d0f4c714d5483a96aff5ba4750f5bdfn/a Quakbot
2023-05-17Ikrghyry.jsjs dfd15bf86d94f5328e101bc1bcf3418f1f1efb46782abaf8219662cc35438b15n/a Quakbot
2023-05-16Xpzcqu.jsjs 3de93e45ea0f175424550b9e785e0621b384a4e4a70452d95316a33e194ea7f9n/a Quakbot