URLhaus Database

You are currently viewing the URLhaus database entry for https://leathertexbd.com/ee/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634941
URL: https://leathertexbd.com/ee/?1
URL Status:Offline
Host: leathertexbd.com
Date added:2023-05-16 21:57:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:53 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 6 minutes Poor (down since 2023-05-18 21:04:29 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Pwrlhctg.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Ngcddq.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Edboyn.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Pcnjyubt.jsjs 3d946e495eb09369ffb75ff08dc4efbd03a19ec53e97d1eafddf4d27c5c11b4cn/a 
2023-05-18Vatgocbg.jsjs fe46365a2844be84f2c3b00d38f7039338747244b46bba5976f29fd3b93040ffn/a 
2023-05-18Ehsywma.jsjs 79b1f8ec256643dd38b44883fae1a1c46e851db6d07560d38f8cb371756b1fa1n/a Quakbot
2023-05-18Bbbolao.jsjs 42d74e9be0d442e0bbebc6134157922913abc72510b235bfa67b53092757a2f4Virustotal results 30.51% Quakbot
2023-05-18Iqqrtkja.jsjs 91a5198c948c77a1f4e846013f6bb7d2ff376ca399e58f825e90cfbaf5c3c773Virustotal results 25.42% Quakbot
2023-05-18Aupwnm.jsjs cd8a39cd43a8cbb2e0c04b201b7df230226fe2dd696ab5c20c9ecbb16cc723f3Virustotal results 25.42% Quakbot
2023-05-18Apopnflm.jsjs 41d25fd2c9445a58f5ae64b05b6042873508bfb85efe4b1b00c3c1b03c4f930bVirustotal results 27.59% 
2023-05-18Vglzvb.jsjs b22c3068eb2fde1d32dd3e2ce301ae348c6baefe0a01c2b50703b10083122ae6n/a Quakbot
2023-05-18Pzcmmsin.jsjs 6d790992a3828c5f421e6c85ac319d61de4eb5320ff67d91b8e5d4577865de5cn/a 
2023-05-18Dvlmcab.jsjs 14ce409dfb31225a9aa73965aca14ef09852a03cf69033bf2deac2a816796a31n/a 
2023-05-17Rlsyjq.jsjs 3f883b067422272c3b10eea88505351741b599d103f66676cb75912106735cfdn/a 
2023-05-17Jlpq.jsjs 555220330c615686c8a042f7d99f74d150a132b4d580ce95d1a7b6db412b77eaVirustotal results 25.86% Quakbot
2023-05-17Aqzy.jsjs f0ba5660e9ba7e62c93207a7b6fd775ee56ae1fa8dfc2ece0f169a6e96076681Virustotal results 25.00% Quakbot
2023-05-17Kcsq.jsjs 029b6f2d9cfb0a2a335c9b9377c1dac9e71206e55f6f82c7d3c0e2edceb9b734n/a 
2023-05-17Jtah.jsjs 831bcd763103748a036135443a32ea80a8d0c311ba22872149bffc13eec6efc9Virustotal results 30.51% Quakbot
2023-05-17Kkgynwh.jsjs ceb8cce48cb241bf1dbcb587ed7d6d8d4c9fdeb5f87bea993602228464eaf9a5Virustotal results 11.86% Quakbot
2023-05-17Eemrj.jsjs 86f81887bb6051cb0f8b8b3d948a6e4bbff1538e986a71386da56590e614f26an/a Quakbot
2023-05-17Flzhsz.jsjs f2a9d6998afa5e7182bce38f7ed813b8fca8a599b1bf449ca0bd9c4c0fc93751n/a Quakbot
2023-05-17Mshsfwt.jsjs e154d366ec4d7b61f663b0e357e21b41c35cb46742614960ff5201e60b45cfbbn/a Quakbot
2023-05-17Hlyyxzoy.jsjs fbff3807222115ad12ddcef1eeb7b75c5a756434e21e6f875800a987a6441b62n/a Quakbot
2023-05-17Gqzepzvp.jsjs e0c1668e36a99dc02c6e8d20ade88d80844d2013ec5d447938c91f38d6af2f0an/a Quakbot
2023-05-17Ctzj.jsjs b9baf80a8048333df9fff8efee43fec87fb6f6d5baecc491ac340a8f57f70fa3n/a Quakbot
2023-05-17Yfsi.jsjs 40118787791d35acf62ee14c62ce40e4a52f2de38ad0057f8865dfe727d110e8n/a Quakbot
2023-05-17Yzrajq.jsjs 05e801f3a8e220dfc62eda33d920f804eec9011a8da49ff772025e3d6cbedf3an/a Quakbot
2023-05-16Gbmhdwg.jsjs bbfc1497be506944ac7f3e67c0de9ee3186c870a0e65bbb9129b39444b889dedn/a Quakbot