URLhaus Database

You are currently viewing the URLhaus database entry for https://flixfallen.com/iai/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634865
URL: https://flixfallen.com/iai/?1
URL Status:Offline
Host: flixfallen.com
Date added:2023-05-16 21:55:08 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:49 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 48 minutes Poor (down since 2023-05-18 22:43:57 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xmxnk.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Qwlm.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Hvkqcilg.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Jjyu.jsjs 1f369bb49a4f522fe1a3fbb89de3b316224c13e56e92c1688424cca47626f3f9n/a 
2023-05-18Tjzzxu.jsjs 3ff223428a9d2b7b897fd823e4add6ae4cc119c86e47eb073bdbf5a578a17226Virustotal results 20.69% Quakbot
2023-05-18Jdbd.jsjs 5b903308829f5c7410c0e53ec748a05a9e2205f4400bf2941199cf2223c0e1f7n/a Quakbot
2023-05-18Hwwsc.jsjs b1580417444140f2311d1f0098c4af6163f27ee7fc99281c6c6904870fdd88e3Virustotal results 27.12% Quakbot
2023-05-18Xhmp.jsjs 69d10bf1c18cc7df540de106a1056c5af79f8b60f1ffae762d06532cc84375d8n/a Quakbot
2023-05-18Dklxojf.jsjs a45416e3d9aa47760feeee7375be42c3748b04b0d9c6c573bf4db2cfa07929b5n/a 
2023-05-18Sydc.jsjs e98ab08e4897807987344800297aa41a72fc207a57b0e89510243b3b8ad0e144n/a Quakbot
2023-05-18Lnbx.jsjs 6e98b0ad9b6fe81e7dde4a5e76cddfdc25b19695ca702e4faf95f45dfc5a65e4n/a 
2023-05-18Efablry.jsjs 447b96999dd079d4e5bbdefc464fbae41be6c1d6f55fa0d6dc0cf9db6f3490b2Virustotal results 23.73% Quakbot
2023-05-18Bfrphuf.jsjs c2c29ea19d16a1a70e365c2161d223994c0610958fe527bfcb605ed47c4a4d44Virustotal results 32.20% Quakbot
2023-05-17Xsfqid.jsjs 8290e44e2bd6431a3cb8fce93c83b97d4710c63bffe7f1eb93db3282ae17b5f6Virustotal results 27.12% Quakbot
2023-05-17Fedzb.jsjs c97e0d75191c3cd583de9edf9cef56be0b4b4bb3e072a64e3fd6133eef6ea96dVirustotal results 25.86% Quakbot
2023-05-17Crxxw.jsjs 4df2da0e1a60159c49866a7e3899e305f80766c9bae6b676bf18955d4e2ee8ecVirustotal results 15.52% Quakbot
2023-05-17Wnzufaug.jsjs 307a3ef8bc1930af1d46fc60bac9820950e278feee14f7a931ac745613568698Virustotal results 19.23% Quakbot
2023-05-17Giujqts.jsjs 4de2124d922958dc3b36346c1906578b79f12a6388ef771a7f8503c21e30af78n/a Quakbot
2023-05-17Xygptg.jsjs d1a92330c8f58a18b81d7ff1a9ea348b205fda7b106c31a2d1e09764a4557fa0n/a Quakbot
2023-05-17Ezlimhsb.jsjs f517f6e7dd7c0f029a72fe25803ac2d5c54c7abcc8e576fbf95cbe6a87759540n/a Quakbot
2023-05-17Zcpg.jsjs 8e5c56c813c3c5f6bff7391956572de745a0efbf88217684bedeed83d736e6een/a Quakbot
2023-05-17Pxoutza.jsjs 8853bcb48e73b346b4657f10d5640b8345f46149c319810be92fc8213a8c4f4cn/a Quakbot
2023-05-17Ofquhvr.jsjs ff148a0485ce9126f2e984604adfa23b8445585c2d7cce0bb2caedc595e7a63fn/a Quakbot
2023-05-17Pdkvibr.jsjs 43eb4737e4252a06f214cff23a01cde27e3ed94b950511470b0237429ad50ce0n/a Quakbot
2023-05-17Ddglowqz.jsjs 65a091083d3d72e307c06f1f2b6f9457ab6023a6d62dcb641195d6e741cc7466n/a Quakbot
2023-05-17Bjler.jsjs fff72ebb9e4d46c0f91f1a861be4f4028062ee3ed487ab6250f0b6f7a64326e1n/a Quakbot
2023-05-16Qvylxlv.jsjs 1d275dda0ec08ae5a7e5daf190c841a48b57d47a991a026bba5bd1bcc87c9333n/a Quakbot
2023-05-16Jzakabz.jsjs 05280a2bd370a993ece48055d9563ea62d3e1665457b3711a6275358e9a538a1n/a