URLhaus Database

You are currently viewing the URLhaus database entry for https://makraf.com/atsb/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634937
URL: https://makraf.com/atsb/?1
URL Status:Offline
Host: makraf.com
Date added:2023-05-16 21:57:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:51 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 30 minutes Poor (down since 2023-05-18 21:28:28 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Eoxwc.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Mzpqyl.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Dderhvq.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Ngbkii.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8n/a 
2023-05-18Vyctdrco.jsjs 2a95cf3c1e69da726dd11f2d5621a546ce89b168fa1cab3506197a63de008d69Virustotal results 25.86% Quakbot
2023-05-18Mdgerhai.jsjs 148afa4bdc9cc4fbfe4816e01d70172a2fba4ead24c822bd4cc936cb0efefaddn/a 
2023-05-18Smigpao.jsjs 4f9c04f40501ff342f07c66108d89ffff23f8fa85ac574a2829cd65a757aeacfn/a Quakbot
2023-05-18Wdoyxzfm.jsjs 9695d2ed6261eeebd78cdc70e45105cb68ff36705197941a93e942a4f861ab3eVirustotal results 25.42% Quakbot
2023-05-18Fzbifdr.jsjs 3fddbe5cee0b2b8ebbfc9637b8f112873fa786d04365ec85c4ff1f3ef1962ce2Virustotal results 23.73% Quakbot
2023-05-18Kbbmj.jsjs 0d6511ddb8cf97d9967367c983015cc45c5ea8c7ae68416f28625637be59caabn/a Quakbot
2023-05-17Hmmaalez.jsjs 6d9b8f4761b3d2b4e1c031cece4e6ae593e6a9e7de18a01dd28c1235bf7900d7n/a Quakbot
2023-05-17Knwnjn.jsjs ba0c34e538207bb899f624292efada218b4202e276606cdaed6e258bd29572b4Virustotal results 25.42% Quakbot
2023-05-17Tljj.jsjs 66131f1f9028038c86ecf420304c739126694a6e99cbba38c1bc18ae9c448ddfVirustotal results 25.42% Quakbot
2023-05-17Iqwtymkc.jsjs 3bb38fa6f98d4d9251f3db4a5374a212389305ea2079c93ed01408cb473d434dn/a Quakbot
2023-05-17Xeqqpzc.jsjs 7e3176dbb2a1721415b06f319dfeecedcc9aa41eb5c53036119f170de1ddc5e0n/a 
2023-05-16Xstb.jsjs 108d53579507a147d49d14012f67ed6cab050db48f9c0add95d4afd77faf1f81n/a Quakbot