URLhaus Database

You are currently viewing the URLhaus database entry for https://fontswiki.com/iiq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634863
URL: https://fontswiki.com/iiq/?1
URL Status:Offline
Host: fontswiki.com
Date added:2023-05-16 21:55:08 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:50 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 39 minutes Poor (down since 2023-05-18 21:35:33 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lyto.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.33% 
2023-05-18Bzqdm.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Qpfz.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Mlhiphb.jsjs 1b068b5090b7ab936769d2ae8d3840defbdf6cec26e14d2359e83bcb5166d443n/a 
2023-05-18Oopwkgpy.jsjs 0651c77d8fadac8f6e3798ca1534ef6af11482867d22cfb20df41d868c3cc727n/a 
2023-05-18Emony.jsjs 43783ef70654df6b8b4c8d132454112d675abe8da1b8cacb358490d7b2159998n/a Quakbot
2023-05-18Gjml.jsjs 32805d4a1cf5298234803410351824aacdf3ae591f390289a3ae325ad6e77e1en/a Quakbot
2023-05-18Gcwrqenz.jsjs 47831ca3235332c96696b1add7425b7dcb044b9de06934992957a5e00cb4dadcVirustotal results 25.42% Quakbot
2023-05-18Fouia.jsjs 294b64c51f30b3884a2067b27a59ddcf4f5c3284a38a7260148eca0e86061a53Virustotal results 25.42% 
2023-05-18Vnwvmggo.jsjs 7ace3a86b7ee25c1f0e953e1c7228cc835205c53e5ed210b4f3b7fc4291a75ebVirustotal results 31.67% Quakbot
2023-05-18Cstsof.jsjs 009f072fec4afeeb62ee51fc61e387113eecca3d907b9784a9e4b79ca0c64ddan/a 
2023-05-18Xyjzzk.jsjs 3bb38fa6f98d4d9251f3db4a5374a212389305ea2079c93ed01408cb473d434dVirustotal results 15.25% Quakbot
2023-05-18Jlxmv.jsjs 6cc345a8ad3df8d8da07821f31095f9c217201e0065038c5bb7e15aae14a9035n/a 
2023-05-17Nemqyuur.jsjs a5ad0d19dd6ae50f16dc5be1921c43a887aba5ab8dae04acbea417a5cd62d61cVirustotal results 26.32% Quakbot
2023-05-17Kmpl.jsjs 865abbd345425ca06fe788a0af4970d985cf2d622cd0ee375cb43dd5567afe23n/a 
2023-05-17Rhzqqqfn.jsjs c7018ff287088c076eb317d0b9402bc9dda25e832c0b205e91a3aeef7468bcd4Virustotal results 32.76% Quakbot
2023-05-17Sfjje.jsjs 15284b1502dbf4c84ff0c772b1ae8788a56987a2e9cda8ba27208e57da59e8a0n/a Quakbot
2023-05-17Hmcadppz.jsjs b246dc6bd29b7f7bf62fa6cfdb10a17053bed892c03b79d0328d384cf96f799an/a 
2023-05-17Mggjrr.jsjs cf3f8bcfc47120345a6bf7e2b44265e2cb07dfc6d6aae1290d5552e5f6d2e1f7n/a Quakbot
2023-05-17Yjlqcerk.jsjs 70b985b09fa574787f8b8ebc0292c53888ff12d01943146d2d61d6183b2afaf9n/a Quakbot
2023-05-17Blkb.jsjs 5bc1e16a3ec5565a053b68d3d6f77b0ae486f1d520ba31b20cc601018710edbfn/a 
2023-05-17Fdxdkqpc.jsjs 8561eab4d7860d31af3cc60232387e92c2556f784986ddb83c729d86543fcd4en/a Quakbot
2023-05-17Vkalitk.jsjs 754824e40487e8964899be89adef32debd5132720e68c071ab8da46f5647ad2an/a Quakbot
2023-05-17Eejno.jsjs db190f5a6081bcc0436a619e975b140d90c28e35d07ac4f0b413054fa3b7564an/a 
2023-05-17Hebh.jsjs adf9190779a841b3f3ab23976e42e3ff8c1d17018ffc042c7cbd3c058ae45aben/a Quakbot
2023-05-17Nwwxcjk.jsjs af2a01a273f3789ee28594727d9f7bc6d168ad26581066bb2a67973b301b9bb7n/a 
2023-05-16Vgnrfh.jsjs 9c014b93a548c6db24544abb60b5742b57681a484797ba714f7de9d253782121n/a Quakbot
2023-05-16Ffrjmt.jsjs 9a676cf0efb0010ea22e04d80cb18efd90a73a2c4cb14c9e5c86b75258055679n/a Quakbot