URLhaus Database

You are currently viewing the URLhaus database entry for https://jbloperating.com/euxt/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634936
URL: https://jbloperating.com/euxt/?1
URL Status:Offline
Host: jbloperating.com
Date added:2023-05-16 21:57:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:50 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 7 minutes Poor (down since 2023-05-18 21:05:43 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bhkjfx.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Yqhxtb.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Doeq.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Hmwdu.jsjs d3495d71d3dc5c68613e3cc5e1af675936d1d35c6cff0025de6e92a3bdc259ebn/a 
2023-05-18Oclcj.jsjs 59eafea575993fa2b9b1a5a60ec2852f5cbda6491cc6c163e79d91e7fc9b1d7eVirustotal results 30.51% Quakbot
2023-05-18Dpis.jsjs cb6a65f1e6220e908455c9dfaf1b69114b9b0c5666dc2b80f597d2c1e4ab29c7n/a Quakbot
2023-05-18Ihwtb.jsjs 266bfb248bbfb5fafc879d0a26c731499ccb3de4c57b64ce4b3a3fc6f836b93bVirustotal results 25.42% Quakbot
2023-05-18Rsowqlfc.jsjs 0b7fccf63d874ff825b5a3e790311b7dd0923c82b142520db78f43a8191e9216Virustotal results 22.41% Quakbot
2023-05-18Wchah.jsjs ef1c6b9ad4a7758ef25a4557fa7bf0a20ab6dd57c36474a91ef75620edd0974dVirustotal results 25.42% Quakbot
2023-05-18Dwijzrq.jsjs 0c002b88627f5df1e7415950b066ddc51bf3e0f4f3ef5a2b01a266b2c4282ee1n/a 
2023-05-18Mmlpoay.jsjs f093b882b8fd4a20a6b626c96af959ed31285d4cd57354e4cf7de124fb062b81Virustotal results 30.51% Quakbot
2023-05-18Nmqyj.jsjs 7f4b255930c48f8c5845c7ee4b70176ed27fac14ad26798578fbdaf327bc1157n/a Quakbot
2023-05-18Bvcitn.jsjs 75203d83c417a2bcd9a5298c46ac9c2befe4e75e7e2c40722c7b8f59a2232c98Virustotal results 27.12% Quakbot
2023-05-17Vjvcwo.jsjs ca9502bdc52560b18884b4483fd8adca417142d736bc92b2039511c11483e4f0n/a 
2023-05-17Mtauhx.jsjs 3302a636901e95a2eb9b66a8fdda7e3cf8997cec8749d879da126651b259557cVirustotal results 26.00% Quakbot
2023-05-17Mdwp.jsjs f39cee789a4050e31f3f61e2dae48c0b5328d480424a439ba3c06fdf7d12ba43Virustotal results 29.31% 
2023-05-17Serb.jsjs be782f3af4554ce0188bf903632e461191f0020d22f70c2760c1f9d32b21bfban/a 
2023-05-17Nwoj.jsjs 0107042269a76269dd71d3dc19e72a1759d421cbf33b9758b94f08c93f0989e6n/a 
2023-05-17Bdjggs.jsjs 9f16a38888bf7c130dfc15dff72eda59b2621e7c1048f157a4cf51e9bcb2e280n/a Quakbot
2023-05-17Zapts.jsjs 548c1db1e3a6ca0d4940449d4cf46d47b423be1e8fed740523d788518ec3234an/a 
2023-05-17Vnzb.jsjs 4cedbeb52a3120b376e502b4067e10f6027c98539894eb5848d98f45864e7607n/a Quakbot
2023-05-17Bgqzr.jsjs f9f5c2538d9e39120ba13c83ee1ff7008320a456286add8cd5cff3b71bac99ffn/a Quakbot
2023-05-17Owiiryz.jsjs 45cbeadbf7195f2031d46a680324c2606e542eb73a1b7645592077c7ffd7c92cn/a Quakbot
2023-05-17Zhtz.jsjs 6beecf7356150e205149b7324b0b58767cfec90ef70e0bfbd40134f53f3221d5n/a Quakbot
2023-05-17Ongpialo.jsjs 4d6127da5a464e549b2306f32b0a790e0efb49a486ae06c537d5512e68b8cedan/a Quakbot
2023-05-16Fmyl.jsjs 2effed8442cc9042c3440a98797c80631e323253e426c2241b8e357a24e215e5n/a Quakbot
2023-05-16Ozlfu.jsjs b7ec48e3b4f04ca90b4f90bb767fac2a4d3b0e8d9fbbbd5668a82d5f1f39178en/a Quakbot