URLhaus Database

You are currently viewing the URLhaus database entry for https://ifyoucantaffordtotip.com/uco/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634920
URL: https://ifyoucantaffordtotip.com/uco/?1
URL Status:Offline
Host: ifyoucantaffordtotip.com
Date added:2023-05-16 21:56:10 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:30 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 23 hours, 42 minutes Poor (down since 2023-05-18 21:40:29 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qpqxigce.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Yatuxg.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Pdpyf.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Gcmfwtvk.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Byyc.jsjs 7e9b5635be76499be2a44bb498252c7640e23a2fdbb2a2979cf0d9e0c65004ccn/a 
2023-05-18Lankt.jsjs 6da5adb44a26381ff077fb8a45c8d20a4888393b3fd5733d6fc8ac4519809c94Virustotal results 25.00% Quakbot
2023-05-18Bhvxa.jsjs 584680760762a6814ff84e38f5de401a9ba356c834f6302e03634c8883180fd4Virustotal results 27.12% 
2023-05-18Tfkbd.jsjs e50fb972f8f78042286895b6d869daf014f5e8082e3c3989ca853daee780a6aan/a Quakbot
2023-05-18Owugij.jsjs 5284d5807da5986ffb17fdd9761066974cb34030eb5067e7f9a65e48b32f37e8n/a GuLoader
2023-05-18Nqbkzpna.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-18Uupho.jsjs 479435405ce11b58fbf16a8d7d4f3f1b2d8952718a2dd79f8c0e4ecb91176be8Virustotal results 32.20% Quakbot
2023-05-18Jpmrza.jsjs b896df419a5e1ac8fe67ede2b9594d6252e8dbf87ef64fd093ceacc52a84798fVirustotal results 24.14% Quakbot
2023-05-18Gbyfyxa.jsjs e097747aa43ca0c5787d98ebdab3ab67fda12444d287a4a0702a670f0b2494d3Virustotal results 11.86% Quakbot
2023-05-17Gybgtt.jsjs 0eb36df6ac7e73e53c148166b06b5c1bc80d6a92c1718e19711dfd219c02ffd2Virustotal results 25.42% Quakbot
2023-05-17Oxki.jsjs 77c78781fbf40291d31c545dd06a094505a49bd415cbeed6b922cafc6af07586n/a Quakbot
2023-05-17Bouyr.jsjs 1c8c07d6d5454652a85d1673775e071cb4068ca92c83d2e45e4cf830d85e56b7n/a Quakbot
2023-05-17Klqxvnbd.jsjs 1226b64c5cdc915647f5412f5ca66ffeb7ac2c6e7787e3f38195da88b68ca12en/a Quakbot
2023-05-17Muzgb.jsjs 831bcd763103748a036135443a32ea80a8d0c311ba22872149bffc13eec6efc9Virustotal results 30.51% Quakbot
2023-05-17Ygwadson.jsjs 813efe88246132a445789b21b1536bd94263cd9a8c7623d7b96a9e5ac755d470Virustotal results 26.67% Quakbot
2023-05-17Cytgqgt.jsjs 78a09834bde88bcf04dd934a793540b810b090e90efb96a977c2477be294fc75n/a Quakbot
2023-05-17Cvqqsft.jsjs dfa59aec9d3aea04d54bc6bcacf0f7a1fc618f9981bc4a0955947134999d2ae9n/a Quakbot
2023-05-17Gnfvwz.jsjs 847e86b3896d2eb3e9e5fd56d8e53ab8ca1a74db922503841a18dbd9146d2bfbn/a Quakbot
2023-05-17Qdatmxmt.jsjs a2c445ebe3a8c64225364457a05a879b5044ad186be2dd2183beff9897111ac4n/a 
2023-05-17Oqrlfcx.jsjs f258859643ca44500a21e79ee493061733b54e857347b256561bf5594ddd4694n/a Quakbot
2023-05-17Hzoakspq.jsjs ce4aa4369fc2f347c39333c702fca4146f4117dcf48c7c993dce8b455055a4b1n/a Quakbot
2023-05-17Zhasrvji.jsjs ed91e919f6dd92cb586b380a04b9ac28cec8c39718b73acc39c64950ec2291e8n/a 
2023-05-17Hctxrg.jsjs 98e0c29f41bb3a87352ca24851bce46ca945eb23119f19d716d76f09d6ccaa75n/a 
2023-05-17Pmab.jsjs 3bc6e4e81531aa05a6d790cec6b697b4bfad2b9b9d3a9fbfa13e0b3ab7fa47c0n/a Quakbot
2023-05-16Xlic.jsjs 0dbbe9a85420a57d02a60a5e0ad5119d997c9b4adb0a581dfce1ba6bb4fb2f2fn/a