URLhaus Database

You are currently viewing the URLhaus database entry for https://kapuasslot88.com/nauq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634945
URL: https://kapuasslot88.com/nauq/?1
URL Status:Offline
Host: kapuasslot88.com
Date added:2023-05-16 21:57:07 UTC
Last online:2023-05-18 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 10:04:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 23 hours, 24 minutes Poor (down since 2023-05-18 21:22:04 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lsou.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Desnrp.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Qpctox.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Lxzlbfe.jsjs 520983ea17e8b75a692f4639a7f509158021a553d09f1933e1d7d12c747a4d4bn/a 
2023-05-18Xdjrgo.jsjs 9992a7c1ac03c78d2395f55820f9ac6e7ddca51d747b443183c09f8f2395f2ecn/a Quakbot
2023-05-18Dtwg.jsjs e50886cba40b1a43e2a678f24566fd07c951a78a554670ec3b2f25a3866d0d57Virustotal results 22.41% Quakbot
2023-05-18Wxetayhj.jsjs d67719607166b2f101544e674067b1d8a66a134620ce0e19794356da09e033ebn/a Quakbot
2023-05-18Ymxjaw.jsjs 33e5253fc3841fb30d4467ba7144f20b94bfb5714befb85aa32837899b33859bVirustotal results 27.12% Quakbot
2023-05-18Jdcmy.jsjs 3833419abb83fe2369255a23b3fa983e65047ca005c0dee0d772efbdbf8ee75fn/a Quakbot
2023-05-18Vmzxgf.jsjs ca0444007c6c56cf207e9de8f069644d774953d9bc532784f55d5deebc62acbfVirustotal results 26.67% Quakbot
2023-05-18Ifczoxsf.jsjs 9695d2ed6261eeebd78cdc70e45105cb68ff36705197941a93e942a4f861ab3eVirustotal results 25.42% Quakbot
2023-05-17Puxgky.jsjs 2c91bde6a534aee746616dd47460479f4813dd91fa6b608246e4cbd908aedf83n/a Quakbot
2023-05-17Yffafyf.jsjs e4e514b57ab086485b47e1413c71a7e9bebc8c84c6615f90bf252d04c98fb5ebn/a Quakbot
2023-05-17Bleuqweb.jsjs b243ce7f5b24e6eab35ff99fcc718064f5897388b337460b05226b50e50b7dfen/a Quakbot
2023-05-17Akva.jsjs 028981687a2254e22ca965537b4ed290d1dca3b0b682da744c55d1763c98565aVirustotal results 32.20% Quakbot
2023-05-17Tiijy.jsjs f4915f167c3fb3624d4d085f3c8bed83ad6edb3d7f55c9b9bb17a4f06111e131n/a Quakbot
2023-05-17Pzalhfe.jsjs 8b5a063138d39c424fbf7ce7022dc972afa3c2df792b3a030272c1c77490dc96n/a Quakbot
2023-05-17Xtefb.jsjs 4a91fb2765da3056fe04bf5254fac9eb72f1fb4f8026845d71ffe672d4daac8cn/a Quakbot
2023-05-17Wlxopnw.jsjs 0062805708689ed861f7ba24d26bc6339e7a12827c676957f5aca81a29af1f3an/a Quakbot
2023-05-17Mvqrtivb.jsjs c01f8abe72f0ac4b8a29bc795f85b7247a073e150a972ab38cf6ee65b10221f6n/a 
2023-05-17Pfutiwme.jsjs 4ca2854214cc586514d0e0fa253cc1d4fbaede9f910ebf6376fd38d37c41aa90n/a Quakbot
2023-05-17Wihmxya.jsjs 35af4a030c96088b675f9de4918ff6d2f859f6976f789513b3d3b4d24395b795n/a Quakbot
2023-05-17Jsook.jsjs 4492776ef0f0c6aa896c805d40c94434f2676652fe295d9dea201e1036af7020n/a Quakbot
2023-05-17Jvrnqaxp.jsjs a5619b2054014dbe72ecdc572d49f9823ae641f14302851626091e1839a92f46n/a Quakbot
2023-05-17Zoeokjj.jsjs 8ef75b94285dbfb1c0749aed64be95d3e7d8e474bad1e0d56d04cd5fd7c98e04n/a Quakbot
2023-05-16Ubbdfhg.jsjs d7c086571cb3afca4bf3efb8fe9bcf53f3579d5bb0be4171a783b09fcf5c80bbn/a Quakbot