URLhaus Database

You are currently viewing the URLhaus database entry for https://gesecuritysystems.com/ureu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634871
URL: https://gesecuritysystems.com/ureu/?1
URL Status:Offline
Host: gesecuritysystems.com
Date added:2023-05-16 21:55:09 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:56:08 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 0 hours, 36 minutes Poor (down since 2023-05-18 22:32:14 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Vxakpvp.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ohhw.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Xxgieilj.jsjs b8176598b3d73a24dd0b5171493b1159401fcb54a868a78ff1f1be72fe8d33f0n/a 
2023-05-18Gvootbs.jsjs c5cd6ca0ca7e79a3c24d0b2e608780ee8eff700153663539c8be58f273a24565n/a Quakbot
2023-05-18Hqcte.jsjs 4a91fb2765da3056fe04bf5254fac9eb72f1fb4f8026845d71ffe672d4daac8cn/a Quakbot
2023-05-18Dychd.jsjs aa49eea2c5b828df4f85742d3d76bc365ee6c18721795dfe567bd8be0b360d61Virustotal results 28.81% Quakbot
2023-05-18Dyhieyvx.jsjs 0b26bdb33f82264e6ee139e028f16f756cf3c276a5c8fdc923aa5d5e2e385872Virustotal results 24.14% Quakbot
2023-05-18Blbosj.jsjs f463f7a1eabfcde6cac3157449992b10b752021a61c46392c383c0949c81a709n/a Quakbot
2023-05-18Edqotzb.jsjs 2971e245d875fcb96bbbbcff59e1a34e0490ae85f5e8abd688b28772bca0b30fVirustotal results 34.48% Quakbot
2023-05-18Ikdzijrl.jsjs 716b277dffdcf3099c8c86e0198ddab7a5d55627de582e5b73e900db63fed67en/a 
2023-05-18Rpnqdtu.jsjs 73b1e3fe01be0b7a83d8ac43d397530b110d3ece6e3ff93d424b36d0b7336aa8Virustotal results 26.67% Quakbot
2023-05-18Vhdsk.jsjs a23cf11c2f986f5d2412a9c98d50dad0b0a02cd2dbbd6fdb1eb47c20cb7dd2bbn/a Quakbot
2023-05-17Ftan.jsjs e21d7ce5a24617b4a823482fea8b703cee1f434028f5ee807b3d77bcb4197988Virustotal results 14.29% Quakbot
2023-05-17Ukrjsl.jsjs 7c13bc2d2d42fdea47cb32e74e359fa9939073a81098e801e04a6daaee5e9ff3n/a Quakbot
2023-05-17Pkddzu.jsjs 8eec4b2ca78d1d8b62a875c3a6b16a0a9053aeaf65f1e6cca22000629ab71432Virustotal results 27.12% Quakbot
2023-05-17Oxyddzt.jsjs 817e3087dd09d826cc20a0381d67784b264c51a854134ac760b9219f49d58f0dn/a 
2023-05-17Pcbqoab.jsjs 6730ba9eb12acff08b5c019bd8587f2cecef533f14a7ca9fc80e7ed001bb903cn/a Quakbot
2023-05-17Zveohdmi.jsjs a533ca0315675319b925cc18170b52d2ed95f2af8281c9c6a6d9e9aa204fdc09n/a Quakbot
2023-05-17Vzjggejp.jsjs 2e8d9d415df71e98bff4a33556d2f36ee72887bb7d23f6ab9672dcf744b4e503n/a Quakbot
2023-05-17Zhxunfs.jsjs 7e806fcf382df797d424e0efdc5da1556b86bd243294bc70cf2bfe977daf8c09n/a 
2023-05-17Pljrujd.jsjs 2bce737675fcc41fe061c53a844ef704d2885bc6b21b2b9ac49a95eaffdc6029n/a Quakbot
2023-05-17Ivxtgku.jsjs 655623f2a11d0d48e9a80d1e5cc85ec860ea51f0f4ab9655c54375b8738ab9a3n/a Quakbot
2023-05-17Xnlshd.jsjs 52c131cb33deb105c23afd432f9bb00d518124a6d91506f63ae6665522aceee0n/a Quakbot
2023-05-17Kaajo.jsjs 77d1603131154c82b650de4510830df750a25fefa391d5fdb66894f240821ceen/a Quakbot
2023-05-17Uwrirqw.jsjs 5e4d05932fe56103146aa0838aed1aaa1d3d30820e48adbac7f8af4bc757ef34n/a Quakbot
2023-05-16Icpi.jsjs a3569f4a142cbb53eab9768aac665dad480ad39184cd82721a0d29f4d84a7ae6n/a Quakbot
2023-05-16Cjqrjly.jsjs f11686969bbf9e81e968f2bb003cc322278cdfbcabeb65f0fd638bac7de819c7n/a Quakbot