URLhaus Database

You are currently viewing the URLhaus database entry for https://cuscotrek.com/ee/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634838
URL: https://cuscotrek.com/ee/?1
URL Status:Offline
Host: cuscotrek.com
Date added:2023-05-16 21:54:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:29 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 6 minutes Poor (down since 2023-05-18 21:01:56 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Kytpagm.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Dcypi.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Szyu.jsjs 44e8e662cec35ad3bc6ab54438d87494d6a3a6a06f257a7c66d717dc419881bfn/a 
2023-05-18Nzxh.jsjs 51351bc77c5c23de367e4fdd74a87fd4ea6a100dd396c2f78dde57c715543f3dVirustotal results 27.12% Quakbot
2023-05-18Aiwl.jsjs c7018ff287088c076eb317d0b9402bc9dda25e832c0b205e91a3aeef7468bcd4Virustotal results 33.90% Quakbot
2023-05-18Xhpnrq.jsjs 13c75bb7b88d3903fbb5263103d8e12f736ce24e98fc6397eb0286451317c087Virustotal results 27.12% Quakbot
2023-05-18Nljrdju.jsjs 959eaab7d50ed2022fc6403b969a196f340861c5aafaa73ebd170ad225699275Virustotal results 15.52% Quakbot
2023-05-18Utfo.jsjs d25526dc27feb5e67f938d4b403a9dad1250e9bad80e8f4d66a22d696dacc328Virustotal results 32.20% 
2023-05-18Rfsavtoo.jsjs c6acb46e483e7792474a50acd3a7ad70626f538da57050c7153b3061376b4f02n/a Quakbot
2023-05-18Wutdehd.jsjs d306257143ef32e3f924f2886ed8c92b3dadea9e12e458ad402e9456a2e61edfVirustotal results 24.14% Quakbot
2023-05-18Grlg.jsjs fcddde4aefcc392bf143eaab986f85fa9fea69d7d232194ecf6c3080b8b60a1fn/a Quakbot
2023-05-18Enbqad.jsjs f15cee857739e493f0b99f7ec002e9fd76dd37b87080807a922a414a5294c989n/a 
2023-05-17Vlafh.jsjs 3cc62e68f657fa870eabb640cd8e651d4ee69a242db9feadeecdbe6a0435ea99n/a Quakbot
2023-05-17Wxpnhlaa.jsjs 621b5cf40077c9b8235e3525da2dea7b28a80029ac3f7ee7477d78c780f4b8c7n/a Quakbot
2023-05-17Fftf.jsjs 41a9ac47a4429134ce75e112f1d067da61f8dc65ee77cd9e494c9434cf179f12Virustotal results 30.51% Quakbot
2023-05-17Dhlnoznj.jsjs bc85062a6ed96ba55f83637c5941ebb10dd8734a7486eb2e716a41e21578b347n/a Quakbot
2023-05-17Iwfsdnek.jsjs 7001d12f0aff0c6712230ed17f0fa70b2b0f2f7f58554663f28e687b643386efn/a Quakbot
2023-05-17Qjyus.jsjs fc9e138d576712bb870d465c8c9568c010f3081a0cee5918a906d5f82a1dfa57n/a Quakbot
2023-05-17Perqcwi.jsjs 5f6e866e73968b7821ac6ef1621aa13b4824a2a94008dbcaf926002db9084eb8n/a Quakbot
2023-05-17Xtmewke.jsjs c0b9b54359af4a5ef1d18eac08420207f62dfcdf3e4784fcdedbbe00faa29285n/a Quakbot
2023-05-17Ahjp.jsjs 046fca902004924b19e61af256bd3a24f576a77290da3a92064ceb97438a7ad1n/a Quakbot
2023-05-17Izufgqmd.jsjs 9bde5efd6d7d3f899462bfd4d801c8084aeda609be5fe0a35a3bb9e02406bf3bn/a Quakbot
2023-05-17Awvmarg.jsjs 5dacef5cd17a96fa33f8e75553a9649bf63e34e6689b99a161fb261be0ac7225n/a Quakbot
2023-05-17Gnpqwv.jsjs 9fee9c85774b018a089c181f5e2b30130d8844125b109e1c12a4a38cce62a9ffn/a Quakbot
2023-05-17Yujwmc.jsjs 428b8541e404a252a62927ca4e0246e5d595a16e8e2e6957f5c939a69c0f1ce3n/a Quakbot
2023-05-17Hhek.jsjs 47344d24a0b1690bbc32b551ee2951c4aa1abf5fe049e511ea65d466b6d242fdn/a 
2023-05-16Rszgpihb.jsjs 56a1ad6c567c474a878bc52143ae651fb51730f2fe85ad29fa1dc36272654651n/a Quakbot