URLhaus Database

You are currently viewing the URLhaus database entry for https://kreyf.com/un/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634947
URL: https://kreyf.com/un/?1
URL Status:Offline
Host: kreyf.com
Date added:2023-05-16 21:57:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:59 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 38 minutes Poor (down since 2023-05-18 21:36:48 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Suiqm.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Mubu.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Kbhw.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Hhzmzmir.jsjs 4abfa5a3237b5be3855c441fec31906f361afa4e4c2498643a6ed6d1677759cdn/a 
2023-05-18Issss.jsjs 285384a5ccf94492475a9af926ddb24dc621f5b0f19df79f8ed7366ca130d544n/a Quakbot
2023-05-18Wormqsh.jsjs 28e8b66452412d01288417d1253f85d6981dd1fe21d53dfb5cbd49822a60cdf0n/a Quakbot
2023-05-18Lqzo.jsjs 56e1630e4d5a2e6b1c2e4e5494d4f0934129788140e2bb2894da4d50c48ece66Virustotal results 27.12% Quakbot
2023-05-18Kaqeobe.jsjs 356f8c2ebf3f6ab97ed37e1195e6ccc8d5441e37c038c0c09c7f481b5aa205den/a Quakbot
2023-05-18Ptueebtr.jsjs 3ac894a6a388d20bc81ae5f8474ee788079f5036842b1542150a55c8fed2059en/a 
2023-05-18Gwtodwrl.jsjs 8aa9df652c080c1ab6754cea7be1a61ae330512a5ddbc9af51177cbeb20da8e4n/a Quakbot
2023-05-18Blnxmuto.jsjs 5c53fc6d6d29d37ae644bf3845ff851d6b03cd26eb5e411f93c26dcf018a4c35Virustotal results 25.86% Quakbot
2023-05-18Qctb.jsjs 99ad6e2718d4fa53c8b3e7479802548afcde5a374d0563ab49ffb0405d8e435an/a Quakbot
2023-05-18Ixne.jsjs a70e07343087b1341505ab67207e4f4d1170a7ae25f9b7c90ca2eab5663e3db9n/a Quakbot
2023-05-17Ezprbn.jsjs 3938ff8a3f26ca0c121f461afcbf7394844e31d1fb9e68757fd98de2a4b3238bVirustotal results 23.08% 
2023-05-17Bubqwsne.jsjs 3bb4e5803055d8c3ad6250df56ce21b663c3da855bc32daa9ecf204060498681Virustotal results 31.03% Quakbot
2023-05-17Trhpdbm.jsjs 0857b5e40844024689620ed0e9d9fbef8b9b295f54e11fba7dd9693f59ce40fdVirustotal results 27.12% Quakbot
2023-05-17Qqbduuyw.jsjs f27926066b5633ef279634f13fac70b4fc198ce37d68ef22e07fa19e4bf0fd44Virustotal results 27.12% Quakbot
2023-05-17Azmbibsu.jsjs 8f5bae7c3310650dc125b9223695f4a40a6d1394f6f6f9dff466a3e53099ba7en/a Quakbot
2023-05-17Jwvoyelu.jsjs f7141b5e0f8768e0c1d39b6da886c311b1ba7a4a1db8d4efe2c936270bc2f0c8n/a 
2023-05-17Crhkvudm.jsjs fc087bbfa79c07ccc635f8a6fd0b89dea00fce47f2c8fdd18e9a29c72d8a3bd0n/a Quakbot
2023-05-17Cgibk.jsjs c61884197987b3584435373de6195e5706e58d590085fddb87aa7d3487e8e7c2n/a Quakbot
2023-05-17Bicp.jsjs 794375944f979a930daab30e0ecfe2995e1cbb74ae72238a78fe1ad42b0af689n/a Quakbot
2023-05-17Wbin.jsjs 3c8c27b1a3fb00d526ab8917db28c044064905af822cbee67c0eef5a6e0c512en/a Quakbot
2023-05-17Ybqsx.jsjs eac07662759db31ce5de355608d4c79434af58f5bf89216cc284e58129ce9696n/a 
2023-05-17Myvsx.jsjs 3c5aa964360ca968d5a6b7e173574e909862fe100da4d2e5284b25b19714f263n/a Quakbot
2023-05-17Qfls.jsjs a37e76c26a62220b27dbb7fa07a3412643d13310e942b50e22d151c73851cb81n/a Quakbot
2023-05-17Kryv.jsjs d1275690fd380da97c282331724922f8aafdfb75d80d6359232e2fe45be95a31n/a Quakbot
2023-05-16Hajfonds.jsjs acba3f9ab59b896c55ce9a7ba7b8e0f2e140b0422744ce8409fcca46e479c1c3n/a