URLhaus Database

You are currently viewing the URLhaus database entry for https://gesecuritysystems.com/simo/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634866
URL: https://gesecuritysystems.com/simo/?1
URL Status:Offline
Host: gesecuritysystems.com
Date added:2023-05-16 21:55:08 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:55:53 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 23 hours, 40 minutes Poor (down since 2023-05-18 21:36:46 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ewmqiupr.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Qtrklbq.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Bjwmeuxq.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Ikavxeat.jsjs 920ed786c47d03bbe7be7c48d92e5d8ec0c9ed6b2b84f8a7f3adaa0571908930n/a 
2023-05-18Yprjuxsk.jsjs f4454d45458f3aaadcdfc328fc4107a6c670b1c0e04df1d476ca56e831b83818Virustotal results 27.12% Quakbot
2023-05-18Nkowydz.jsjs 41d25fd2c9445a58f5ae64b05b6042873508bfb85efe4b1b00c3c1b03c4f930bVirustotal results 27.59% 
2023-05-18Efmm.jsjs 5195290a6bfe72d1709c08345d0210181ab60e363339796ef44c05a17d9c03dan/a 
2023-05-18Hglc.jsjs ea84f700c5132b793e8bbc20dd9383bd71e86ffe8be7ec16ec7fd5ada9cfb33en/a 
2023-05-18Yfsabp.jsjs d5310c601c98c90eb1149ea53a24b05711bab888bf14ec14f88d5c7bb5dd59ban/a 
2023-05-18Oqci.jsjs 86f81887bb6051cb0f8b8b3d948a6e4bbff1538e986a71386da56590e614f26aVirustotal results 25.86% Quakbot
2023-05-18Xpbsv.jsjs 56e1630e4d5a2e6b1c2e4e5494d4f0934129788140e2bb2894da4d50c48ece66Virustotal results 27.12% Quakbot
2023-05-18Arflio.jsjs a2f17ffca655028bf5663349090771ded5e0eac6f65e71d0fc151816a2dc7342Virustotal results 23.73% 
2023-05-17Vjkxm.jsjs 119865e21bd0f564ac17f9e36940d9360139b87392fa02dce3483f1a789ab4abVirustotal results 24.14% Quakbot
2023-05-17Wqjxb.jsjs 07d1842292aa2619ebfbb551eff5580fb24f945283f3de4298dc06f9493b6b20n/a 
2023-05-17Mckm.jsjs b11ddd3e32db780631dee2546f8eb8498cf1976976b4f9b6229279881aff3e12n/a Quakbot
2023-05-17Hofk.jsjs 6e988a313f3e3723e109adec17cbf1513010e50c972114a245ebf3ed743e84bdVirustotal results 24.14% Quakbot
2023-05-17Rlou.jsjs 4fe762f3bef37ff2896345d647489f0ee60515aaf5da2c93572e1088e91adf79Virustotal results 28.07% 
2023-05-17Eiodrpzw.jsjs 2ef6e700c619c1ace05075497393d8ac827d836ec052de9b6a71a0cdcd343141Virustotal results 24.14% Quakbot
2023-05-17Ubbdo.jsjs 2643a0ad4d4922d9f4428188cfe85112015c48ec78826051b8fc118affc60fa4n/a 
2023-05-17Dgspwl.jsjs aa472c7e7b56d86c076ad98dbef43eda720643b65f43c94da7c1b2ea4dbfae1cn/a 
2023-05-17Jhpwcl.jsjs 83b77dde734842bf968d5129cda577e348e48c1166aa27aa981eb736c6307a1en/a Quakbot
2023-05-17Vzkvmox.jsjs ea110f19360b7f39ad03507d325537bcf3f0e4e93571c632986c7d19ce69119cn/a 
2023-05-17Ogwpu.jsjs b98e2ef2033eedc1a943c88180544178b7816550d5a2c7a8b8ec00ca3819175fn/a 
2023-05-17Dpgiguyl.jsjs b070fd7d6316168f259c584fd70d77d3f229c78316f5a19d34f9a31441a054fdn/a Quakbot
2023-05-17Qnpva.jsjs f385e920a6077bf8935a61d2557fd369efdeeb997c5fc8bea03fd8fc2e75687an/a Quakbot
2023-05-17Gajol.jsjs 92fcdf05a35b6f5db31b8cd89d4e4113798b19448a8690d48dac10fb884b14e6n/a 
2023-05-17Mzonxxiw.jsjs bd25c5a4d39cc8ea9d9868dc65b975b38039bb9e1a27efa435234127862c0201n/a Quakbot
2023-05-16Fajshtlf.jsjs 4d7ee0a77e6c34de4117a93f269389aa09629fd4ee1d4b6a20cb96aec93bfca7n/a