URLhaus Database

You are currently viewing the URLhaus database entry for https://gdpakistan.org/em/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634882
URL: https://gdpakistan.org/em/?1
URL Status:Offline
Host: gdpakistan.org
Date added:2023-05-16 21:55:11 UTC
Last online:2023-05-17 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:56:12 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 23 hours, 16 minutes Poor (down since 2023-05-18 21:12:13 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lxdkvg.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Zoylvjd.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Qpmkyh.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Xaaimr.jsjs 7dac45bbe49dcc33e841c8e4f9b7a294cfb563790807448bb1759e1d38b4684an/a 
2023-05-18Prqxj.jsjs 1ef243d363359aa7c5d8ab0a55ffa52a9302f63a3750df5b8408c99641bb9ab9Virustotal results 27.12% Quakbot
2023-05-18Wlhh.jsjs 403516fd88c6e48a70d5ab2c1e966024e8e46c5403dcaa8dbb3b56774715cf30Virustotal results 25.42% Quakbot
2023-05-18Xnfjsimx.jsjs 576d767be1b5ee880a56263521aef9366435f9ff583a68aebc426d7da2c02e2aVirustotal results 30.51% Quakbot
2023-05-18Dkoywtkp.jsjs 6bb7a104fe821f46f0853eb826d375aefd2c29fca71738cc3494e5cd9ad1c40dVirustotal results 30.00% Quakbot
2023-05-18Hcpl.jsjs dc776fb044bb27e20a16f383ecdaa44a67be283f4902ddd48f1f6cffd24d036cn/a Quakbot
2023-05-18Exiscclt.jsjs 0eb9fa07ffbdae465ca7afa7b68b6b38311315046844cd6ac97c9e3b77d5fe99n/a Quakbot
2023-05-18Ubjpzr.jsjs 43f0a123b00abe19f1412b6fff2944e5bf4436a2ba20e3493ba9708ee5088c8bVirustotal results 24.14% Quakbot
2023-05-18Hhddc.jsjs 0727eef30bd3d52541c3e05de818415c77f77ce68db06ea425431972136cf8c7Virustotal results 32.20% Quakbot
2023-05-18Tawnuyq.jsjs 66a44d6ecc0bff8550c4f8fd93b40851e019bac6297339dd180d268ed9bba451n/a 
2023-05-17Kzqctq.jsjs b866fb32a73c9c9a6de4c2fa92651d4d8d7f72f0fe66af797867274e8a889e85n/a Quakbot
2023-05-17Vhuob.jsjs cbc57ebccb343515692b47782246ac3ce19ae8ae335ddc9895810261d11cb663n/a Quakbot
2023-05-17Tgxjcit.jsjs b80551abdf45ba18befb113fb4c02517cb49680bde72f8ae92ef07e61857ec89Virustotal results 22.03% 
2023-05-17Dooqff.jsjs 4779dbaf4f01d866b1dd6a2cdeb855c53a82951952ba41e9af73be849bc9116bn/a Quakbot
2023-05-17Yiocrcwt.jsjs be782f3af4554ce0188bf903632e461191f0020d22f70c2760c1f9d32b21bfban/a 
2023-05-17Lrxc.jsjs d6e5d8bb312aa607d892cd90a910040c5ff30ee3a76f41fd9c177f3c09b59f21n/a Quakbot
2023-05-17Sdcfl.jsjs 94482ada3a27f9e8cf8f7b554597969eef03e0593d496ba95205fdf735ed010an/a Quakbot
2023-05-17Hspdhblo.jsjs 9010e9724ad8af62f363efb35ac02bfb4af695c727c4f55110c173e826075251n/a Quakbot
2023-05-17Iekpfnn.jsjs 1aba13a7ccb24b9ffdee39c5762b57a690f177f5d350959c6ab9edc6ac314b9cn/a Quakbot
2023-05-17Torbqzp.jsjs 99bedc47575372e4b187488ff7f91f1cd5361d5fee15980f473e5255e39f2a38n/a 
2023-05-17Uaevwm.jsjs 5d243a3918e6ec3fb5006dcc174d7758f257f05c3ab7690ad3d1c357145417abn/a Quakbot
2023-05-16Ipmqmdw.jsjs 0eed9b27857e3141fa8c4c0eb99b81c5325ae99ada76c43093f9972554a34458n/a Quakbot