URLhaus Database

You are currently viewing the URLhaus database entry for https://kinkyplaystore.com/elmt/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634964
URL: https://kinkyplaystore.com/elmt/?1
URL Status:Offline
Host: kinkyplaystore.com
Date added:2023-05-16 21:57:10 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:20 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 39 minutes Poor (down since 2023-05-18 22:38:27 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Orpoi.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Xphqwcka.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Qqnui.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Zzgt.jsjs 7c8f37897c959ddfb85a5178c812e0d4dbd6940e85c0257be7f397e8484ce18en/a 
2023-05-18Mtylc.jsjs ebe8f7530444ccce930ca2eb9bce9d1a8dc83786f22d231c9b0ecc1b37803d8aVirustotal results 23.73% Quakbot
2023-05-18Uukn.jsjs 50ea4195ce44fd0c177d6c8bca4b2a4f34676b3b8cbddaa734fe11cf5a265f01Virustotal results 24.14% Quakbot
2023-05-18Bboo.jsjs bcf9e05bff1a4453dbe187a142eddb6857e41bbaf3869f7ddc598b6ddca0d276Virustotal results 26.32% 
2023-05-18Erahzvjq.jsjs 749721b74088db119de7bccbe5cea0c9486f42bb570461ff262c5ed324b4ca16n/a 
2023-05-18Cyezlyi.jsjs b7a9d786648f1049f8c0964593b9fa3983e6066f5674ff98d438cf5ec9d592f4n/a Quakbot
2023-05-18Dryw.jsjs e21d7ce5a24617b4a823482fea8b703cee1f434028f5ee807b3d77bcb4197988Virustotal results 14.29% Quakbot
2023-05-18Vwfyjcwh.jsjs 4657c8d962a15da8cdc6ff3c1ab3d492a89eebdd09249e8d29eea382791500abVirustotal results 28.00% Quakbot
2023-05-18Nchpx.jsjs fb2bca8ce3aa4207fc636e9ebc34bb47cc0d9b6a233352bff3b6875b6bedce3dn/a Quakbot
2023-05-18Agvagdp.jsjs 229271acfd7face73c4919f8ae74ec7e9e3d276810827e045c7ee12baf2e75bfVirustotal results 30.51% 
2023-05-17Gvkpmrq.jsjs f7e8b96be3ac805e339ea8216ff018b90165280b8feba0fb873973b6f18ca747Virustotal results 27.45% Quakbot
2023-05-17Vvzv.jsjs b207edc0255d1a287ff3c8f2e769e9540966bfb78068188cac44e1c350f704a4n/a 
2023-05-17Bfarmlc.jsjs 21fe5b84a05703a96f7e89bc1831bd5ef93ce9c6e1afe08259006454a502ba59Virustotal results 30.51% Quakbot
2023-05-17Msknsmm.jsjs e50886cba40b1a43e2a678f24566fd07c951a78a554670ec3b2f25a3866d0d57n/a Quakbot
2023-05-17Yavsi.jsjs 0651c77d8fadac8f6e3798ca1534ef6af11482867d22cfb20df41d868c3cc727n/a 
2023-05-17Pxfzme.jsjs 562698d61476d96d6f3b0fd847585b9c5e4d1f9eb96f8153ba577725aa0eb697Virustotal results 27.12% Quakbot
2023-05-17Mrznu.jsjs fc35a5a51f420de2456b7dcb8c59dfcfc4a5a995abb8201286aa81cd0c391508n/a Quakbot
2023-05-17Ouxgvg.jsjs 358c18a5680bcc83f9988659d251f9ef38a4a624f585eb27f743c16b9928f387n/a Quakbot
2023-05-17Yvklhuy.jsjs fb1aa635d4cbd303aabea8af6143e10a8398642f982d05ceaffa954196c95d56n/a Quakbot
2023-05-17Jnkobiv.jsjs cda3e6002f9e88516f8a79dc3bfb4da36c61da8bb615e0796183e09e02969ce5n/a Quakbot
2023-05-17Uqsfeya.jsjs 68cddbc910af035fbd6a2e86e1d5afde73cec3d409fc1495e22ed2373cd90c0en/a Quakbot
2023-05-17Hklkix.jsjs 426865529e287d8c7d18638bf9e6619825f4dc5f0789dfb006fc84026351813en/a 
2023-05-17Ubzqu.jsjs 9d618e1603e23917c3464c9339ca441ea98d7fb96e5fcc9cc4414350931b590en/a Quakbot
2023-05-16Wswrw.jsjs bf5814c496b0754898ac3660a220b13672514240d6811ed0b4bd9af06b8d5a96n/a Quakbot
2023-05-16Jdlul.jsjs e39e046bac76aadb6eafa41c8330ed504f8b5b454bc147ec364d1025141faff3n/a Quakbot