URLhaus Database

You are currently viewing the URLhaus database entry for https://kapuasslot88.com/or/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634961
URL: https://kapuasslot88.com/or/?1
URL Status:Offline
Host: kapuasslot88.com
Date added:2023-05-16 21:57:09 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 10:04:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 23 hours, 36 minutes Poor (down since 2023-05-18 21:35:29 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qskqpnmx.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Zuyassc.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Ycrimqj.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Onqxmc.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8n/a 
2023-05-18Ougay.jsjs 3315fb16775f4485223d1934b50a92867143966210e39daf3e2314e6a8af1c9cn/a 
2023-05-18Wggrijy.jsjs 03cdab834b6a7165627af8e82df4d52dde740aa3481625a88ef76e122b7b2894n/a Quakbot
2023-05-18Xruugyiy.jsjs a357a8a9b62674cff6660b76659f4cd36ccd979d44937371bde57235d81c392en/a Quakbot
2023-05-18Gaceyyg.jsjs 2c402bf5ac40a8110c89bcf0f4ccd617ba22f8e8a6ca32d9949461c82540e48aVirustotal results 28.81% Quakbot
2023-05-18Owuxca.jsjs c1460321f81f5ddaf0e6965fdc14511326240b2d261c1e2c98e92f73eb1accd4n/a Quakbot
2023-05-18Gwfxcerw.jsjs 2bcfc438cf9c0a4f72832a134f6709c7596645ff3d738abe3b2fd53250ed50f9Virustotal results 22.41% Quakbot
2023-05-18Vdbhst.jsjs b246dc6bd29b7f7bf62fa6cfdb10a17053bed892c03b79d0328d384cf96f799an/a 
2023-05-18Zrsdt.jsjs a4fb26b40f74df15f85f6ee98f0faab524e9434e8469ea400fb9e1d4a53e6505Virustotal results 28.81% Quakbot
2023-05-17Orhrxgg.jsjs b896df419a5e1ac8fe67ede2b9594d6252e8dbf87ef64fd093ceacc52a84798fVirustotal results 24.14% Quakbot
2023-05-17Dbnlaa.jsjs 9ac768cf3025869132bdb78aad3f4505cd8dd7e5ddc218e64d6645ba8db5e4f4n/a GuLoader
2023-05-17Gyqqhb.jsjs 8b2b3c3498bea970b5883a908b36e4437b9809a010cf2df44004264d33d66dbdVirustotal results 11.86% Quakbot
2023-05-17Lpqxrz.jsjs 0c7c96dd589f0bc1676f7af1371bc70cbf50d310293d070ff8e1fef3df4533f9Virustotal results 24.14% 
2023-05-17Kwysm.jsjs 683503e1ee6accf36b4e270156fa48982aeb9619157f07c35c1dbbfeb8a43e7dVirustotal results 29.31% Quakbot
2023-05-17Ktfu.jsjs a581d1bc0926e4888a7d919a2ec529d51e03862bf784ac4cd4333e3df168d239n/a Quakbot
2023-05-17Bnlu.jsjs b4b9340a057e2f27555df973e95af7d75b991cadbf943c5f48de2cbda1e3edcdn/a Quakbot
2023-05-17Xsabd.jsjs 731ce377211ca1fa3b6232fc7514f9958633382d35b86f20b1d73d46658667c5n/a Quakbot
2023-05-17Kiot.jsjs 5de21e639e5050c3c92eb0ae8e24c898d29360b0cec6112c2163b8f57037b09en/a Quakbot
2023-05-17Jixgb.jsjs 74b3fde1392101021bd7eace63cefa3983defa2aea7f00270596943cda27579an/a Quakbot
2023-05-17Shzxdxqw.jsjs f36cc46f5fa7040fefbf6c6b28b5a4440503927fdeeaa4e58f4d5a39ff17a995n/a Quakbot
2023-05-17Onzyuwvq.jsjs f7091858309dbd6f7e97feef1dba44d26abeeb5d44dd898590612f9775c73531n/a 
2023-05-17Xqozgok.jsjs 1f995e69dcbfedeede13b9edccf782eee59c52ab3ad5125117937b9b9d032e95n/a Quakbot
2023-05-17Arhwm.jsjs 6d7fdb3fe0a67be0abb98bdac69317f0376542fdc7b743c8d833d0fa1f85d374n/a Quakbot
2023-05-16Tnrpodh.jsjs dbece228d963bfd33f8f8e4b3c9af6cab50fceea6a2aa0c39b70a617188a9692n/a 
2023-05-16Mccsk.jsjs efe1c28e1da4c06dcb076d0ad644943c8861525d6915da9dcc758d5760e89a07n/a Quakbot