URLhaus Database

You are currently viewing the URLhaus database entry for https://grupo-cala.com/li/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634904
URL: https://grupo-cala.com/li/?1
URL Status:Offline
Host: grupo-cala.com
Date added:2023-05-16 21:56:06 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116894 created on 2023-05-16 21:57:03 UTC)
Takedown time:2 days, 0 hours, 42 minutes Poor (down since 2023-05-18 22:39:07 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bfyowcjr.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Bwrksgvm.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Ihrcqeov.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Ylzxgl.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Yppjiv.jsjs 9c8da21730bd6ca998a21290326c34cbe7d5153ef1da6b8f1b55ee78bd6bd6d1n/a 
2023-05-18Dxntpif.jsjs 1d6e41a96832fff256d4c07d7cdb318a251230e1445351f5ad36b87ce958bf1dVirustotal results 25.42% Quakbot
2023-05-18Gvjumah.jsjs 0b26bdb33f82264e6ee139e028f16f756cf3c276a5c8fdc923aa5d5e2e385872Virustotal results 24.14% Quakbot
2023-05-18Tdfiwp.jsjs ef1c6b9ad4a7758ef25a4557fa7bf0a20ab6dd57c36474a91ef75620edd0974dVirustotal results 25.42% Quakbot
2023-05-18Lodsw.jsjs a3a82b0e5a194f3c627df166b34ee132214dd6dd7f04b7a684d1b93af75f7591Virustotal results 32.20% Quakbot
2023-05-18Bmrzmq.jsjs fbf34d1f59eea01ae0ec44fb3d7e93d4a06dad0b411065a5d6292f3ebe7081acn/a Quakbot
2023-05-18Zicxq.jsjs a64cebdd853596ce95beeb112b9dfab6eab26ff09b77eaad1c909cb1b6cff48an/a Quakbot
2023-05-18Xaltv.jsjs 35a99626b0db91409ed1ac874964033c1490a20549ae611e95fa7f81dbd98d44n/a Quakbot
2023-05-18Pcarjom.jsjs f72249d2446e19299c3e74d70064253963b884cc61a402aaa18a78e044f901ecVirustotal results 31.03% Quakbot
2023-05-18Ynmo.jsjs ed3b42a466d5debc63224e8439d69996fd4f174cfcae800ac31dd8dcb69c921dVirustotal results 31.58% Quakbot
2023-05-17Daldqjuy.jsjs 2c91bde6a534aee746616dd47460479f4813dd91fa6b608246e4cbd908aedf83n/a Quakbot
2023-05-17Vvvuqmd.jsjs 7cfdf6db2bcad8f5b911ac39a8da45e6a8bc3e53c287742c8afc09821a544c0fVirustotal results 29.31% Quakbot
2023-05-17Ynsdmv.jsjs 29d88d7a73d988b2b2c5ddc76ac150742366a2a8c379758bf47f13c2fcf01346Virustotal results 27.12% Quakbot
2023-05-17Qpnsny.jsjs 5fe1ce92222b0ef2d0fe599c26907689fbeb05acb3c14dcc9cd468d2db479a26n/a Quakbot
2023-05-17Yrovw.jsjs 3f2b1d4fe71004830b3afc87d735391d7ff0033d3264baf0b9b84903c52c16f4Virustotal results 30.51% 
2023-05-17Iwaypakc.jsjs 9aa3958dd376fcd792957165b53999bc05bdb411a0ea61e30b7787e1a7cdfbf0n/a Quakbot
2023-05-17Tdychbvj.jsjs 2ea57f7ed2c3148b87f87bed297e9f780f369a71667342ed01a88fc779a24eefn/a 
2023-05-17Kowkmlk.jsjs 7fb7f2fca09ef6ac133062a5f4b7088140d08c20c2e16b1dd760b6a2d91c0608n/a Quakbot
2023-05-17Flwc.jsjs 4802dd1698a48c7e9fabfa7615496b92c315300acca4869ea94e991a66feb225n/a Quakbot
2023-05-17Qlkp.jsjs 911a09564b510a62fd1262036a0abc3e2e9bd28506d5b07be31e9bcb464ea625n/a Quakbot
2023-05-17Jsqrkqz.jsjs b72356213951d43a0ef205487b84ca2a3ad86a1be364d21fd003691b185ce501n/a Quakbot
2023-05-17Mdrevr.jsjs 87c6002241ca331e527450da7df34d725c12dce7564d7fc0d2dce16490dc94b3n/a Quakbot
2023-05-17Uhfbqzw.jsjs 4e6a0e44cb14cc5bf4e119c07e38b95339417243c183f61e4c32eb70df93b362n/a 
2023-05-17Ieohg.jsjs c9dbd2a1ba70c14d4ac5094fb060804d18cbc929d5939882c12d1b7c2320e486n/a Quakbot
2023-05-16Wlmbd.jsjs 396d7deb7d520e84dfa5e6bf2dd184a7b3e95d735ba3e1ebca4882a208212a34n/a Quakbot