URLhaus Database

You are currently viewing the URLhaus database entry for https://creexpobyhre.com/lodf/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634829
URL: https://creexpobyhre.com/lodf/?1
URL Status:Offline
Host: creexpobyhre.com
Date added:2023-05-16 21:54:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:19 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 36 minutes Poor (down since 2023-05-18 21:31:56 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ezhpcxrm.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Nolp.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Hoxq.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Xniyudk.jsjs f92e492850703c3acf5258b36418b3a17e666d23bbd872e03b9537f7c9e241d5n/a 
2023-05-18Kkkcla.jsjs 5fe1ce92222b0ef2d0fe599c26907689fbeb05acb3c14dcc9cd468d2db479a26n/a Quakbot
2023-05-18Ydljqs.jsjs 0d6511ddb8cf97d9967367c983015cc45c5ea8c7ae68416f28625637be59caabn/a Quakbot
2023-05-18Hypts.jsjs 0259d5d40b143ebaaf60af05f38a325f660c922eb6201a18e664d949c3be13a3n/a Quakbot
2023-05-18Ucxjze.jsjs 90d7044e2b3c6695b8ce4be887d9fedf198e2631c47d77093e427bbdc2ff19fdVirustotal results 29.82% Quakbot
2023-05-18Nkgv.jsjs 7f1024ee7a57ad586eb6a36dbb25ba4f7e78cbd55b3c87d5209716b7628bc53cVirustotal results 28.81% Quakbot
2023-05-18Exvf.jsjs ceb34fba0cd428a9dffee10f6b9c5857bfe8e363974adecbd1c42b994a5bb36cVirustotal results 27.12% Quakbot
2023-05-18Eiuk.jsjs 2971e245d875fcb96bbbbcff59e1a34e0490ae85f5e8abd688b28772bca0b30fVirustotal results 34.48% Quakbot
2023-05-18Uotuvq.jsjs 66718c6f0ac9419d7f5bb30cef5272328e503b226e7ee6157072e26782f6421fVirustotal results 16.95% Quakbot
2023-05-17Gegojykg.jsjs a5e07fd19c36096b65281a4da6788fdb724e4cc4be6fae21497a969c1255a622n/a Quakbot
2023-05-17Vdmxyi.jsjs fc35a5a51f420de2456b7dcb8c59dfcfc4a5a995abb8201286aa81cd0c391508n/a Quakbot
2023-05-17Oisz.jsjs 59eafea575993fa2b9b1a5a60ec2852f5cbda6491cc6c163e79d91e7fc9b1d7eVirustotal results 30.51% Quakbot
2023-05-17Iktmkiir.jsjs 6da4a8bacb02c6d1b3251c5978545168c0712fb14b5ec2731a867b73a3daeacan/a Quakbot
2023-05-17Rqdk.jsjs c6acb46e483e7792474a50acd3a7ad70626f538da57050c7153b3061376b4f02n/a Quakbot
2023-05-17Mnvqkzob.jsjs 345e76a5091b5ecf319a57a8901fc203f48dae4dcc62b70fdc4d1e542d1a1f46n/a Quakbot
2023-05-17Iziedyd.jsjs 53b3144d6c4d4163d5317d32d6bfcc11069a721edc167234c3599a6e2aae5274Virustotal results 25.42% Quakbot
2023-05-17Gkun.jsjs dc2082d0e27eabe3ed96fdbecac723d76fcbb6897709edc0b6e8a7a9a9ef177en/a 
2023-05-17Efzlh.jsjs 600e7eaced8463492986260ea18a680fc582be3e40bd979bee065bd5272955c9n/a Quakbot
2023-05-17Mnzuou.jsjs 3c58ff71a05768b4ac5738c600b880c9ba0101795d3baed7adfccc6010cb9a86n/a Quakbot
2023-05-17Zlpgtt.jsjs 59c2f4c008f061fc205d1f4ef55114a3b02ed85cd00f125d54f840f873859c5bn/a Quakbot
2023-05-17Esaym.jsjs 65540bd9e201a3a7c73bb7bba063780be40822002281662fb5be409a3772e274n/a Quakbot
2023-05-17Boqluo.jsjs 66439ad58da8ff176707735e66ae9e1fadf6594d1fb1ef9af2348bf1ffb03189n/a Quakbot
2023-05-17Wcqelmco.jsjs 858e8e8383e7628c8c53c02e552e4a74f370201ffff56cf8b59e12d1d55c9c0bn/a Quakbot
2023-05-16Svhdfbfe.jsjs ed97a9ef984871f7b8b992d1a13de1a7ae0bd6268394a911e4da7d7b698e9e50n/a Quakbot
2023-05-16Qowg.jsjs 77ea762b739795f77ee5ad251005273b9c4b173dda6be4fb1f8e1d0122736f39n/a