URLhaus Database

You are currently viewing the URLhaus database entry for https://ifyoucantaffordtotip.com/oiup/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634910
URL: https://ifyoucantaffordtotip.com/oiup/?1
URL Status:Offline
Host: ifyoucantaffordtotip.com
Date added:2023-05-16 21:56:09 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:30 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 days, 0 hours, 49 minutes Poor (down since 2023-05-18 22:47:14 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bjwd.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Xuixt.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Vqozvguq.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Fden.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Padmjzc.jsjs ff74beb6f389d9c33d2695f1c550429e751e59889bdc10b03e6c4dcecde85504n/a 
2023-05-18Hcnmcdgm.jsjs 16cf6bcb57e5b6fbd88357c73a7c2e1fea2c60e1facf1122d4f6d9ef672f908cVirustotal results 31.03% Quakbot
2023-05-18Stwpo.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2Virustotal results 25.42% 
2023-05-18Ftsemku.jsjs 7f5092d0b223ae713b6ead45d62c1c63d910a500fc960aeae16e1a1073355c86Virustotal results 25.42% 
2023-05-18Nlznw.jsjs ac2f114a6bac8df9444849169360217c9656b866153cfc42dc444cbc6b7b6e35Virustotal results 15.25% Quakbot
2023-05-18Cwfviho.jsjs 1c527faebea66510912a82a4ece923294f74fa2947ce89b48b9b341ade828e1en/a Quakbot
2023-05-18Jlltoinp.jsjs 479435405ce11b58fbf16a8d7d4f3f1b2d8952718a2dd79f8c0e4ecb91176be8Virustotal results 32.20% Quakbot
2023-05-18Ixdrnzy.jsjs 076515d52f5219c37701ac4b38e72e4f6a809dffce463343615c3fb079c9ec89Virustotal results 26.67% Quakbot
2023-05-18Oevbh.jsjs 0836ece78eb77f4b5ebf101fc5e4317ad5554305bff6466db565f247b93b5928n/a Quakbot
2023-05-18Kzpwiivf.jsjs a8a8153cceaada2e2ff92961844812b0aed9cd17ebb6700ebca64bc3627c960bVirustotal results 28.81% Quakbot
2023-05-17Sjsjcvq.jsjs 0473836cfc335949eae38f3049dd3932d818dc6cbbe8c178f72c74370912d088Virustotal results 28.81% Quakbot
2023-05-17Oyyqwezl.jsjs a4633a3bade267edfd4e6171fb238320ca7b8fc6ce56403954409c8af38c4ca5Virustotal results 27.12% 
2023-05-17Ylgxe.jsjs 288d425513bcbc2368880669d2eb2f2b553edb8962acfb77e4a967d751235520n/a Quakbot
2023-05-17Qoahx.jsjs 33f33ebc5ae78bdbf3a9afc064c64f1121c0214e1305d5567232cbc8779ab8c3n/a Quakbot
2023-05-17Bdrkjcxa.jsjs 74e7f951fe5dcd84fa5c570a1b2e27991662022a85a90f8f38cff80d462e8541n/a 
2023-05-17Unczqm.jsjs f4fb9e206467712813d87a31c0ea3285bf1a5ad9658839ca77ac0a61dcbf0693n/a Quakbot
2023-05-17Bkdhp.jsjs fa6d3526e896cb3ecf22f942020f813ff05b231a0755ca03e5588b547131c9a7n/a Quakbot
2023-05-17Oqmtnojp.jsjs 2177d925f10e2cd3a5d175b8e14d8faa7413f6cd18da6fc7832edca35cdb5aadn/a 
2023-05-17Gvxp.jsjs b9c338b6152d890a76680cec3ab451619334bbd63748a63521d278a0f143d2f1n/a Quakbot
2023-05-17Soepaihk.jsjs 8b9c99f946d6a4bdd5ba67cfd90a8208ad94d2cbc7420bab9f8f9b2b206f7b97n/a Quakbot
2023-05-17Ecoffpec.jsjs 56242fe599a0269096797c451bb78aa221e0ae9fda2f1b09b8bfd17f1b7832b0n/a 
2023-05-17Behmt.jsjs 08022413e8a8fec4480eb6caca44d0c8fae50716648f5288b853ce7a78cb13e6n/a Quakbot
2023-05-17Upig.jsjs 74ac426dcc96a786b86fd7f04b1f49e590b5089c86d695d71a4a51c52a8d5e75n/a Quakbot
2023-05-16Iaosh.jsjs 0a281deb36cfda852e9212c9a1b0a46b7e4304dd86a7db8d1d7be14d39b53459n/a Quakbot
2023-05-16Yzhti.jsjs c2aa371743c226e5e0018934451a21f80623bcac8108fdab91c6017c8a93ff33n/a Quakbot