URLhaus Database

You are currently viewing the URLhaus database entry for https://gesecuritysystems.com/lov/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634875
URL: https://gesecuritysystems.com/lov/?1
URL Status:Offline
Host: gesecuritysystems.com
Date added:2023-05-16 21:55:10 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:56:08 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 23 hours, 6 minutes Poor (down since 2023-05-18 21:02:31 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Idgrshmg.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Cgomwifr.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Ocimgp.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Sgmosj.jsjs 95bc0cbd0679f45f80aa732d36c9f2220c1a677321eb5f98302d8707d928d149n/a 
2023-05-18Otuuchj.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-18Nyflrwl.jsjs 6bb7a104fe821f46f0853eb826d375aefd2c29fca71738cc3494e5cd9ad1c40dVirustotal results 30.00% Quakbot
2023-05-18Soyrimze.jsjs f72249d2446e19299c3e74d70064253963b884cc61a402aaa18a78e044f901ecVirustotal results 31.03% Quakbot
2023-05-18Wyiblsry.jsjs d7efcadce017eaba7ee055cac3f1fb9842bd54107fb46729f546ede523c09e5an/a Quakbot
2023-05-18Qlrk.jsjs a2fee1f921c59d61590ed86bdd9e19a12b68d9722d228d0e5bef678bd31d461bVirustotal results 30.36% Quakbot
2023-05-18Ddjd.jsjs 34bf72fbc4370971ff89c72391aca2a8a5b37aac3f1cbb8f2ab5480a3df6ae0fVirustotal results 32.20% Quakbot
2023-05-18Llxoz.jsjs 60483947f59c4a843833ac5302fae111fb318dafe639770153154f7e01c2afa9n/a 
2023-05-18Zzrto.jsjs 15abbc922de384ed273fbc1a2e831ab1024bff793998f2cea3c69abd68a85566n/a 
2023-05-17Giycfo.jsjs 2a95cf3c1e69da726dd11f2d5621a546ce89b168fa1cab3506197a63de008d69Virustotal results 11.86% Quakbot
2023-05-17Yoiuj.jsjs 0b3324b249fb9e33cb3970056ed6166b271c1f678d65d34cdff6079bbd95f2c5n/a Quakbot
2023-05-17Oenzltdq.jsjs a5f0035e2f6ab21d643775a304ea994d963bc0ad712a5ae1a9ebb1a5298f7adbn/a 
2023-05-17Mkxwuwpw.jsjs 16cf6bcb57e5b6fbd88357c73a7c2e1fea2c60e1facf1122d4f6d9ef672f908cn/a Quakbot
2023-05-17Bmiaftz.jsjs c6a62ee43c36edd934b0aecf8cca18487dbc8612228decd3f37357b043e4e85dVirustotal results 24.14% Quakbot
2023-05-17Xnoxwdgd.jsjs 9b45c4614db7627fee14ec88aef1faf7e97115a9755ad170998bf331df8c2b0dVirustotal results 27.12% Quakbot
2023-05-17Vavrcjyf.jsjs dff43d93176f7f0b50d2b960680eb78be307c219d3a2f9b42d969390818a467fn/a GuLoader
2023-05-17Cpvqbr.jsjs 4337cba8b78547b868734310e496077583649a8b18899d47b6c36b0399e09441n/a Quakbot
2023-05-17Rhfsby.jsjs 5bda3fc17d1b062d0f864d3a7be5ca32dfbfc4b2d479c9fede2e4c84f094ab85n/a Quakbot
2023-05-17Nmopat.jsjs 4400ec1b31507bda7efcf717abe416862dc4cd06bb81a68ca61653d4297fbdd8n/a Quakbot
2023-05-17Ntsjbxzn.jsjs c5a98e7444dc7b9cfb1e1c87e9e674af28b52d37ac7846201ecf50872349747bn/a Quakbot
2023-05-17Qxioo.jsjs 9ada69f6d0df05ec7fe4b1c3f789c7a407afc110db55f9288f8ed084d27a6091n/a Quakbot
2023-05-17Lwlvww.jsjs 00826b9806982efe886d8003a16a05decd48d961572c751f87c003d4ae9f9d61n/a Quakbot
2023-05-16Lsjsbus.jsjs db8a1ce4551d83e2f991431396f8bb63c50b6b22518a7ae5520bea5a93eb3dd3n/a Quakbot