URLhaus Database

You are currently viewing the URLhaus database entry for https://flixfallen.com/eeil/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634869
URL: https://flixfallen.com/eeil/?1
URL Status:Offline
Host: flixfallen.com
Date added:2023-05-16 21:55:09 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:56:07 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 31 minutes Poor (down since 2023-05-18 21:27:45 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Puvj.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Xbynm.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Yblzle.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Cmgxdz.jsjs da3ea3ffa3c3021b35bbe55a2210d01184547bd009492126dada2924bcfb2c62n/a 
2023-05-18Fridibob.jsjs 6be55c4c2824a4cd16aaf9002adae153b6156ce58174febfd162d82dff7ba019n/a Quakbot
2023-05-18Oxmetp.jsjs 27d3fa3ffa307f97bc3047f15898d338734929484e224f43ab8740c710601a78n/a Quakbot
2023-05-18Fbxjfr.jsjs 2971e245d875fcb96bbbbcff59e1a34e0490ae85f5e8abd688b28772bca0b30fVirustotal results 34.48% Quakbot
2023-05-18Oprh.jsjs 58b0e516ec4c36b4a0582314a01bc968a5e3a7acce646abe2179ef5adde91a24Virustotal results 27.12% Quakbot
2023-05-18Zoapka.jsjs 71122ff461bd77e00f131eb7f52d813ed7a1fdb3262bba2adb83ee04085152f9Virustotal results 34.48% 
2023-05-18Nerjg.jsjs 7aabd12a63a4289e6a5f5fc62d866ed2ade8e917a6f2d203bdfd37c0f87ab265n/a Quakbot
2023-05-18Bapk.jsjs 4fe762f3bef37ff2896345d647489f0ee60515aaf5da2c93572e1088e91adf79Virustotal results 28.07% 
2023-05-18Eeio.jsjs 42b8297467af3118af88bc8bd71bc4b1cff09e2fdd17dd631cda319c5c4cf592Virustotal results 24.56% Quakbot
2023-05-18Ofocxirr.jsjs a9d658acf1c13639bef4615e65fcd8eaebd3b1d0c14ee826b7268e893878e5a5n/a Quakbot
2023-05-17Mhdjnj.jsjs f9a03e213a2bf36d23d4a6877af8261834b3049ed458410c5e8b4c6da00e2383Virustotal results 27.12% Quakbot
2023-05-17Uzaw.jsjs 32b63b6f4ee01c7737a32e2bfd61aca2c688fdbd79e9455010a3a5506954ff0an/a 
2023-05-17Rjjofnew.jsjs e8a4b575211295a78e536c4a374d5538f24470f6036d3a1e5ab52f149b6a5683n/a Quakbot
2023-05-17Aftihwsw.jsjs 8319c01bce9a24d28eeb4e926938d179f37c880ab2aaa26290056ff5089ceae2Virustotal results 27.12% Quakbot
2023-05-17Ijll.jsjs 2ffe30857db286ab5839fb47499480fff446371b3c1f8df2d8dde6853266f088n/a Quakbot
2023-05-17Qpdppwtz.jsjs 9f83e5346339db98db754ee60a6d9de3db2ecaf650f4590c2a11ad9e484c46a2n/a Quakbot
2023-05-17Njkfzuxh.jsjs dfe2be80a982bce1f10ffdd78081f5aa7e64bb878436347e9f43418d8b127a29n/a Quakbot
2023-05-17Pvoy.jsjs 7824258fdad5c7e7d930b53d2a0e91bb2d617840fb911daed6f0fcc31a5f9a29n/a Quakbot
2023-05-17Zysqey.jsjs 4a66af6942df685a2be717c05b91607a32a8f35f8bb4a39780186b45c3438eefn/a Quakbot
2023-05-17Qcmflc.jsjs 66f36428d559723f5c7ce7794be782fafe443c11bff250c000ff56831facd0b7n/a 
2023-05-17Cqdn.jsjs 5cd9fe3cb867ec8b082bd5b0be39f93f6e0b3175e7088f8f3715a30efb5472dbn/a Quakbot
2023-05-17Pbzc.jsjs c4a443955a45b7a035589eab7d0f8fef9e9bdbde80467ce668fae1d22af0b6e8n/a Quakbot
2023-05-17Svmqvog.jsjs a4a78ad73597c583ac9b717dc1930a36a53452109c4fad0dcea415e9cd33045en/a Quakbot
2023-05-16Toagndup.jsjs e029289821067eef928c225a1b6c540e5059c7a247f39d239d188c798a7fb58fn/a 
2023-05-16Uzinj.jsjs 402e487e2b6d99bacae5998cae9b0d607a4124bac16aa50ff5d1e7a262a3116en/a Quakbot