URLhaus Database

You are currently viewing the URLhaus database entry for https://guest-house-adria.com/im/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634907
URL: https://guest-house-adria.com/im/?1
URL Status:Offline
Host: guest-house-adria.com
Date added:2023-05-16 21:56:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:26 UTC to abuse{at}avalon[dot]hr)
Takedown time:1 day, 23 hours, 6 minutes Poor (down since 2023-05-18 21:03:37 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Iwyl.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Kndrp.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Nsowvc.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dn/a 
2023-05-18Wwktpyoh.jsjs abdda4c6d8c817d793d751807f39dd2cea7ab501b2d145e7bef5bbb6243259efn/a 
2023-05-18Grfwog.jsjs 2c91bde6a534aee746616dd47460479f4813dd91fa6b608246e4cbd908aedf83n/a Quakbot
2023-05-18Fani.jsjs 32786105579d9ee90c2b3e3c5c1aa115af93c9931e8629901c02b41150fa1636Virustotal results 27.59% Quakbot
2023-05-18Nsdjy.jsjs 8772156f90eaf1afea7ef8aede91a10a14f6ab0bbfc0cb8629917994af09f843n/a Quakbot
2023-05-18Nhbsbp.jsjs f95ae26c9bf7ecb6970afb88bfa12c71eafd8b35160d2c1658e57d36ea915477Virustotal results 29.31% Quakbot
2023-05-18Owuortgt.jsjs ccdaaebf2ae2ce525ab5ccf2b4d74cf6b58e7d9515c21c0d46e2b8e0709eefb6n/a Quakbot
2023-05-18Xurcmvti.jsjs 0281a8abb9cc25356770caa1340573c19ab7bda7d5303f43a60a52b2b9154067Virustotal results 25.42% Quakbot
2023-05-18Yxar.jsjs b80551abdf45ba18befb113fb4c02517cb49680bde72f8ae92ef07e61857ec89Virustotal results 22.03% 
2023-05-17Dhor.jsjs 0d6511ddb8cf97d9967367c983015cc45c5ea8c7ae68416f28625637be59caabn/a Quakbot
2023-05-17Skpm.jsjs 86cf4c93687b588dae11523a8db9355990fe06f4481aa096e4acfcd8555b8e25n/a Quakbot
2023-05-17Ojzjodj.jsjs b896df419a5e1ac8fe67ede2b9594d6252e8dbf87ef64fd093ceacc52a84798fVirustotal results 24.14% Quakbot
2023-05-17Ybwy.jsjs 34d43862c3788ec764c7fb735ddcfc1f1712a66632a3bf7e8b83cadc98a6faacn/a Quakbot
2023-05-17Vysbn.jsjs 1c8c07d6d5454652a85d1673775e071cb4068ca92c83d2e45e4cf830d85e56b7n/a Quakbot
2023-05-17Fshiizj.jsjs f16b3c48ca1ba324e53c48a72c3bc53329423b16779e1cd1d0d40447f39cfefaVirustotal results 16.95% Quakbot
2023-05-17Avuha.jsjs 5ed6c54055399ee6ffdf3adfc06337fb1dfa9ee1a6c1766091b74c1ebe2ebda1n/a Quakbot
2023-05-17Vcxpv.jsjs 61b08d9dbbce48ff47a9d8eb8e60e57ec7d11bccbd5495f1b178aab7779de32fn/a Quakbot
2023-05-17Uolxvdl.jsjs 4af68f81fe01a76ca6fd0c39a807928b24f16427bff165be9047334b6b1efe36n/a Quakbot
2023-05-17Fifjxng.jsjs b82b120db90ac6099ac207e67abd187b0748f2c825557f54960724e619b49d09n/a Quakbot
2023-05-17Nplz.jsjs 20d6b669f921f6239f1b4bfc7bb847ed2a46564b14c2b5772973463b85580219n/a Quakbot
2023-05-17Hbhzy.jsjs 91c9d7f98f84497174c6d6cc15c05e10fb27f621b44578fe7a4fafb83d13afe0n/a Quakbot
2023-05-17Edsbp.jsjs 6471a3753eee3785f0e0db827880cf8055a8ed68f69e7a4cc50682510b7e4649n/a Quakbot
2023-05-16Zufrp.jsjs 8a0310b261a2a0c2a4edb61c6d4b5ecd6982f54f141a977bea1f40d7ad708f01n/a Quakbot
2023-05-16Jtssac.jsjs 40f3811f4e686cdd57b6c31e9272885603e8601fea16344de1104e4afbc10faen/a