URLhaus Database

You are currently viewing the URLhaus database entry for https://globalchoicecourier.com/bas/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634900
URL: https://globalchoicecourier.com/bas/?1
URL Status:Offline
Host: globalchoicecourier.com
Date added:2023-05-16 21:56:06 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:19 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 14 minutes Poor (down since 2023-05-18 21:11:34 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ljqdayi.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Pjicf.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Teyov.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Hhcvs.jsjs b866f780c381794ecc0ecc27c8925bfc5d5c441e118a3558d4075610d8ee12a7n/a 
2023-05-18Pjbitoqh.jsjs 16fe8055701bf9e829e70c4811b31fc75aec4d03582697ab493fd530e84ac6cdn/a Quakbot
2023-05-18Ibdtw.jsjs 36c1b7c7a1b5c11ac465725f40b235b232adb02f122a1d9d3210656cacf4ee3fVirustotal results 25.42% Quakbot
2023-05-18Xzzv.jsjs c5cd6ca0ca7e79a3c24d0b2e608780ee8eff700153663539c8be58f273a24565n/a Quakbot
2023-05-18Iknc.jsjs ccdc371fa95a2dc8192ecf73826f489942857addced0e8ce4b9aa969aa98381en/a Quakbot
2023-05-18Bkad.jsjs 2878ea27fb0bf41510c5a442c350ea2d31a71ee4c1532dcabf74f79b9aa1b3f4Virustotal results 28.81% Quakbot
2023-05-18Ceffta.jsjs 020f938e3e5a80465883b947cf72e1604c794e693956eee1cc4707135129fd43n/a Quakbot
2023-05-18Xvqo.jsjs ba7f993248a05baa4fc8af51ce3e8f89889e817065c4b964cb37bfc088ae75d1n/a Quakbot
2023-05-18Badqyuaw.jsjs 6a2c26dc0efdfc1c4fdf83525f29de723f3f77f866558ce277756af920925c89Virustotal results 27.12% Quakbot
2023-05-18Mchq.jsjs 7cfdf6db2bcad8f5b911ac39a8da45e6a8bc3e53c287742c8afc09821a544c0fVirustotal results 29.31% Quakbot
2023-05-17Iplbjrd.jsjs 41d25fd2c9445a58f5ae64b05b6042873508bfb85efe4b1b00c3c1b03c4f930bVirustotal results 27.59% 
2023-05-17Ihlyxswx.jsjs 1a6bded230cdd64243a37dd3ca94385ac9f1c4794e054250311bd99f2564c83eVirustotal results 25.42% Quakbot
2023-05-17Ojlsmbqv.jsjs 4ca00c819ac67574145c0664985afbfd757621b4809ec157f14d22108aeacf8dn/a 
2023-05-17Iztq.jsjs f39cee789a4050e31f3f61e2dae48c0b5328d480424a439ba3c06fdf7d12ba43Virustotal results 29.31% 
2023-05-17Yfvl.jsjs f15cee857739e493f0b99f7ec002e9fd76dd37b87080807a922a414a5294c989n/a 
2023-05-17Rwplmsw.jsjs 621b5cf40077c9b8235e3525da2dea7b28a80029ac3f7ee7477d78c780f4b8c7n/a Quakbot
2023-05-17Tpeotg.jsjs b3d737c721d3c5e7e58a28f076c7fc26e6ebaab2f08f52e645c645c0b8536210n/a Quakbot
2023-05-17Aujkfmy.jsjs 7bfb69f48fc4e6755321a306b281ce0cef6df4cea4837b262ec717b5717979c3n/a Quakbot
2023-05-17Mdzv.jsjs 33acb0d922838e29cf9aead9e2e95e07c42defafa936cb5b192074cc023cc850n/a 
2023-05-17Twvbor.jsjs 4872141de9e0ecaf42bbf260b0892dc849fceb97cdbbcf0d0ca035716589d9fen/a Quakbot
2023-05-17Ykxife.jsjs 1bc7a65ab3bca829d14446de7fa86ade0d297f91ccc8f504f556de5f0932c896n/a Quakbot
2023-05-17Pelb.jsjs cbce9388fb4acc5fda9f434579124e86aee965bc5923bc0503aca85a2a9da1f1n/a Quakbot
2023-05-17Thgxj.jsjs 1297ab1cf1cd3aee580a25d9062c62dbe76e42700f5a6ff0a4d445ab5551efb6n/a 
2023-05-17Mgov.jsjs 12ad3cb91ce1cddcaa052c9e114d514fa8fab475a7d483a697af8954606114e6n/a Quakbot
2023-05-16Oeqpe.jsjs 53fb0434d1dd4d208845f1ab35b0a18af76142403b0e1e64c1b0425b586c728an/a