URLhaus Database

You are currently viewing the URLhaus database entry for https://cuscotrek.com/uapr/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634835
URL: https://cuscotrek.com/uapr/?1
URL Status:Offline
Host: cuscotrek.com
Date added:2023-05-16 21:54:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:29 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 13 minutes Poor (down since 2023-05-18 21:09:27 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Cporabmv.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Xeoaem.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Etdnwagi.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Ghzgppy.jsjs e6d610bba59d281f1df238d79c463aac3be9003a5998870081ec814ea67ac840n/a 
2023-05-18Vrwkw.jsjs cfc68b43d74cf7d5fd05920f53d7e80393899308fd60fbcd60c8582770294bc1Virustotal results 29.31% Quakbot
2023-05-18Emqyaw.jsjs 148afa4bdc9cc4fbfe4816e01d70172a2fba4ead24c822bd4cc936cb0efefaddn/a 
2023-05-18Reuvqmm.jsjs 621b5cf40077c9b8235e3525da2dea7b28a80029ac3f7ee7477d78c780f4b8c7n/a Quakbot
2023-05-18Wddcxd.jsjs da4bf3b68417dffef143d4e6c343ee8adb0fc59559ccca0c4ba48cd6e3e1e5f8Virustotal results 25.42% Quakbot
2023-05-18Vplm.jsjs 0a976cddfcc0bc1b5776cc8cce0d9d1c9fbddfee4017434169358a45936d3ab5Virustotal results 27.12% Quakbot
2023-05-18Dcyke.jsjs 9f16a38888bf7c130dfc15dff72eda59b2621e7c1048f157a4cf51e9bcb2e280Virustotal results 32.20% Quakbot
2023-05-18Esxrrjhf.jsjs 9898858b1809b1511e09fbef76498bfa2d39365eb70958ac81ba4a0263c6e209n/a Quakbot
2023-05-18Psfthl.jsjs 2bcfc438cf9c0a4f72832a134f6709c7596645ff3d738abe3b2fd53250ed50f9Virustotal results 22.41% Quakbot
2023-05-18Prwb.jsjs 6a36fcdbced70acfd047d3132e249ef81960cf97f62f9e391e672db0ecd19f13Virustotal results 27.59% Quakbot
2023-05-17Ezamfm.jsjs 3b413252866f0b4261ccf3b4972d86690f29353242c85733133be84940ad6fa3n/a 
2023-05-17Icuu.jsjs 60483947f59c4a843833ac5302fae111fb318dafe639770153154f7e01c2afa9n/a 
2023-05-17Wvhzhing.jsjs 928de378e1b8690de67deab709ed80da406ac542daf31e7c5859f02c0b9a4240n/a Quakbot
2023-05-17Vbyfav.jsjs 0836ece78eb77f4b5ebf101fc5e4317ad5554305bff6466db565f247b93b5928n/a Quakbot
2023-05-17Yjucp.jsjs a74b08fd8574636c900a77d9d50f0c7d91b058b6a82d501d33a366e1e7c3d343Virustotal results 25.42% Quakbot
2023-05-17Lgfzrfp.jsjs 0e3f95cec4063907bf68a435963ea684b5f9bbcbdd4ac6337048ae70087a81fdn/a Quakbot
2023-05-17Dgfy.jsjs 94aab6d39b072cfdcb3e75abffc7e259d06b8450d12d7d9d248dd75357c9f1bcn/a Quakbot
2023-05-17Rqgl.jsjs 13ae439ad35e033d04cf5bbad7c70d879f6800b67bc66e4d626a6b30250ac845n/a Quakbot
2023-05-17Kzffhnfg.jsjs 4fa6adb63b40b02a2f00ea502dd41690cda7b120a12cb6c9fa8b5ceebe180ce1n/a Quakbot
2023-05-17Ackcjen.jsjs 775885699f23122a8b5b7ae00974b0af85d13eed778b98753fc1c811f7f13c43n/a 
2023-05-17Jchfpb.jsjs 20aeca7c5950a85f11d5358660cc5ff9aad190c5b980ef304665e8635ecdfddfn/a Quakbot
2023-05-17Pjjvu.jsjs 2289d97cf248a3d6201ae640ff5e75f11f14fb23935f296199ea39ac9966a250n/a Quakbot
2023-05-17Vtagxw.jsjs cd28d50efeafeadeb842be360aa01c2b304a2c2b0b76108897201987234f6f19n/a 
2023-05-17Sqre.jsjs a601e08b3b41ffa3f808b1c17fecfee1756b828945032dfed9528357a6abc3bbn/a Quakbot
2023-05-16Kgwkhss.jsjs f7111e38d99c117c10a5bfe48da1d9505bd5c8f17b52088b298af0011be4a27en/a