URLhaus Database

You are currently viewing the URLhaus database entry for https://kdjlivraison.com/mu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634953
URL: https://kdjlivraison.com/mu/?1
URL Status:Offline
Host: kdjlivraison.com
Date added:2023-05-16 21:57:08 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:58:02 UTC to abuse{at}hetzner[dot]com)
Takedown time:1 day, 23 hours, 27 minutes Poor (down since 2023-05-18 21:25:03 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xdfjjqf.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Fzwzx.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Ezxjx.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Plglio.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Bqlzoiip.jsjs 0693465b48ec60c86aa1dcfa43c4a9f59cebf49e24a05a9f662f1f8450401a94n/a 
2023-05-18Arhrxlce.jsjs cac584e2ff62f01ca51db682d0b6d32ff11123c3bc3b6a5e9794606ad51844fcn/a Quakbot
2023-05-18Lweti.jsjs 16cf6bcb57e5b6fbd88357c73a7c2e1fea2c60e1facf1122d4f6d9ef672f908cVirustotal results 31.03% Quakbot
2023-05-18Metzj.jsjs 5fe1ce92222b0ef2d0fe599c26907689fbeb05acb3c14dcc9cd468d2db479a26n/a Quakbot
2023-05-18Zgaxgpi.jsjs 55ba4dfbf0eeacaace5287a51196c8d2e3c7ae79a65fd07a27fd6024ca40bc13Virustotal results 16.95% Quakbot
2023-05-18Gtvyt.jsjs 6b64266f2b4feb2f9f045a12882dd0a54819e4eb7d840e0c0c092944b0a8ef11n/a Quakbot
2023-05-18Wbrkqxd.jsjs a9d658acf1c13639bef4615e65fcd8eaebd3b1d0c14ee826b7268e893878e5a5n/a Quakbot
2023-05-18Rsuua.jsjs a93a8bf8a31ec8306c9567bf9a32a827765ff0e798aacba99ea917a481f43f7en/a Quakbot
2023-05-18Krec.jsjs 7237114103b60a76ef6a67916d0d6fc1e14dc707087bd27684d1093748393f39n/a Quakbot
2023-05-17Vdly.jsjs 64dbefc6ce8b2caf9b441a36490ebed30319eed28e49ddf95d43659494906f10n/a Quakbot
2023-05-17Mpvhaq.jsjs 009f072fec4afeeb62ee51fc61e387113eecca3d907b9784a9e4b79ca0c64ddan/a 
2023-05-17Umjlb.jsjs a2f17ffca655028bf5663349090771ded5e0eac6f65e71d0fc151816a2dc7342Virustotal results 23.73% 
2023-05-17Qngmxvm.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-17Orowzl.jsjs 5002cf2a22a794f451347414eae921d359f14704e2fc3491ec70ae29266a6ea6Virustotal results 22.03% Quakbot
2023-05-17Avlswtv.jsjs 80f6fd82b28ccaacb151e0447865a17ab4711eefd8ab38eb96bff981a7077a9eVirustotal results 28.81% 
2023-05-17Adcr.jsjs c1460321f81f5ddaf0e6965fdc14511326240b2d261c1e2c98e92f73eb1accd4n/a Quakbot
2023-05-17Jfyzao.jsjs 9f58336c0b0f6cde0a91dbee871cad45a315c5413863ef2b29affc9c949ee72dn/a Quakbot
2023-05-17Xhyszqyo.jsjs 3d8640286249ff409e6f25415ca3c3e5ebc20466437a98db8e64e970f21fcd78n/a Quakbot
2023-05-17Inrwlz.jsjs 343eee8757b83646c3db6f87d6a3281e373f72f4766fdea5d9da63f3203e579cn/a Quakbot
2023-05-17Koqaqos.jsjs 19be7366c4a0fb1d0ea4fa6e9e671ffe05ae7c3a056cdb2fd580d7328aa298efn/a Quakbot
2023-05-17Gmbo.jsjs 1fc2727641b99e3c90710ebdcf71aea601a61c072fe1c572c13388933cde9838n/a Quakbot
2023-05-17Ckgfchy.jsjs 4c5b5d63754af659168246730b46660be3f69c188c2a7d78372e08e22feda2d5n/a Quakbot
2023-05-17Zbsk.jsjs 7ee0b76d21b6cacf635789bdd637488ec42b7f6b914bc28122cb7e251d763397n/a 
2023-05-17Humuy.jsjs 69eb6fabb76e564edd1892906fe24d5b2dea9ef77f4efa6e2314492a7849ea83n/a Quakbot
2023-05-16Fesziz.jsjs 44934d46bbe5733b2395ebb259b73bf236a30488ef8d833028ca8f240beba3d4n/a Quakbot