URLhaus Database

You are currently viewing the URLhaus database entry for https://efficientadjustergifts.com/rcs/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634840
URL: https://efficientadjustergifts.com/rcs/?1
URL Status:Offline
Host: efficientadjustergifts.com
Date added:2023-05-16 21:54:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:26 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 23 hours, 22 minutes Poor (down since 2023-05-18 21:17:45 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Myrug.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Zqntr.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Zewrre.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Nqgtk.jsjs 04ffc642ec3d8109224f1a5dcbc09c0e3ebd697a6ce8314963b0ca3b480a1e1cn/a 
2023-05-18Wqwc.jsjs cac584e2ff62f01ca51db682d0b6d32ff11123c3bc3b6a5e9794606ad51844fcn/a Quakbot
2023-05-18Qdoznkdw.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-18Blcjrl.jsjs 8c854caf958691cbcce8d6a84edd87a8ead04c306a6a625c058d479d3b472059n/a Quakbot
2023-05-18Bqtrdhwi.jsjs 8045c5474873d54e74acd15fa59448b63e4a6d443562ce14223f30374924a094n/a 
2023-05-18Mmjuoimi.jsjs 03cdab834b6a7165627af8e82df4d52dde740aa3481625a88ef76e122b7b2894n/a Quakbot
2023-05-18Hddbdmm.jsjs 6d5e3d77360658771bba4d35e8dd94a77d30f33a7c30ab86b66e271b54d2a638Virustotal results 20.69% Quakbot
2023-05-18Shvcjkn.jsjs 31bfb0e9f32a6891aa3b4bb9c1caeefec664295de95b74eccecf9eb67a2b84cbn/a Quakbot
2023-05-18Rspezvsy.jsjs 7723afb8d2a1417a6f0c808e628394b609e66227688064323ce47b25cb0505bcn/a Quakbot
2023-05-18Zlkm.jsjs 9fc5c95367df0d42df001590faddb4edf2e71a19e7159cb210d5525553462459Virustotal results 15.25% Quakbot
2023-05-17Qxjad.jsjs 287c569bf794a7ec47dcd5f308d39f138b6b4b964ad50c335991038cafd9d476Virustotal results 32.20% Quakbot
2023-05-17Fxicwj.jsjs cee11dd3e06833ff80c75ab19feaefb05e62b347d9ed97e9ecb8f4ac5a889f95n/a Quakbot
2023-05-17Rchuwxdx.jsjs 6730ba9eb12acff08b5c019bd8587f2cecef533f14a7ca9fc80e7ed001bb903cVirustotal results 30.51% Quakbot
2023-05-17Jacblfj.jsjs f6d73eed4ee4cb252294f53568ea49c055a4a65267b79e8491ace852655d5575n/a Quakbot
2023-05-17Qbghuvch.jsjs 817e3087dd09d826cc20a0381d67784b264c51a854134ac760b9219f49d58f0dn/a 
2023-05-17Afof.jsjs 67878c5898e4d6118aea2d8059896ec493c2cb1b7f3bdc563068504a0bca9373n/a Quakbot
2023-05-17Cmzk.jsjs 8853f1c5c38715c4c6371fbaea63e61f4301cf54a2c0b9ea435b28379ac57742n/a Quakbot
2023-05-17Yvuiwt.jsjs e76b6108ce1ba19fbd15130b2d1c0e94119017bdd519b32d5933726cb4239219n/a Quakbot
2023-05-17Sfastvk.jsjs 1cfe2783d761aaf5fc1da1ba8640f909437c6037d6050e3bbba8190749d63481n/a Quakbot
2023-05-17Mbdvooa.jsjs eac7934dd608d91ee774c273da7e4a89ea4344db89355ea35e12e1eb82ff3675n/a Quakbot
2023-05-17Uwiuwc.jsjs ed3db5c7fd155335b4c05fd8aad12211f5479c1dde344ae1417ef0519ddcf0f2n/a Quakbot
2023-05-17Xxgluy.jsjs 37dbf019cc885cfedb4c5ec32f0a144b8430c86939f909e3dc6de715502e6a91n/a Quakbot
2023-05-17Ucfmi.jsjs fce14034d0816d0ee43609d641fe271eb25d68779672574d2ae89c4cd70c325an/a Quakbot
2023-05-16Zztp.jsjs 686e909632e3033dc89d53a90f2d1932622f017832a354c0e8190e5a6dfa956en/a Quakbot
2023-05-16Qgsixzrm.jsjs 407d7edf3b465eebb385af28ee0d9687d6c033b228024e66818ac171f4dda4a0n/a Quakbot