URLhaus Database

You are currently viewing the URLhaus database entry for https://martinstvs.com/qq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634973
URL: https://martinstvs.com/qq/?1
URL Status:Offline
Host: martinstvs.com
Date added:2023-05-16 21:58:05 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:28 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 23 hours, 3 minutes Poor (down since 2023-05-18 21:03:05 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Yeliwyyd.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Tbwf.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Llkqghgl.jsjs 0f1a9d40a28989681e377a40de08093911c216783a1788f50b87d223949c1ab5n/a 
2023-05-18Kkxahsb.jsjs 043c810fd7d77672928841fc44891531ce536c6b4cfb9a4e54529c20b36eecd2Virustotal results 30.51% 
2023-05-18Lucibmy.jsjs 962531faf5a4bccd1d88868db9f0b5a79c3073f110ae5e4b9f61d7ea15f8b855n/a Quakbot
2023-05-18Cpouljmq.jsjs 6d790992a3828c5f421e6c85ac319d61de4eb5320ff67d91b8e5d4577865de5cn/a 
2023-05-18Tvoa.jsjs d6e5d8bb312aa607d892cd90a910040c5ff30ee3a76f41fd9c177f3c09b59f21n/a Quakbot
2023-05-18Siorl.jsjs ee8f7825f5b87fbdb90f5bc8eff0cfadc358c64cfca2dcb37acfd398d5b2f201Virustotal results 26.00% Quakbot
2023-05-18Uxrjudkb.jsjs 2ffe30857db286ab5839fb47499480fff446371b3c1f8df2d8dde6853266f088n/a Quakbot
2023-05-18Dqtkxqii.jsjs 4fc44d998f2dd5c9dd8a2b1113af13a124201f3cd8b1f55511976b52294ef5e7Virustotal results 23.73% Quakbot
2023-05-18Kipbhmjw.jsjs b93e7c1a5d378e99de142cb47319276288120a8138977edf98875c43822f6d86Virustotal results 31.03% Quakbot
2023-05-17Fwckemzs.jsjs 7a515185d1c204dc897de0e485dd2dd335341156b5b7764220fb6df27fdbeb16Virustotal results 25.86% Quakbot
2023-05-17Afctcewg.jsjs b5e43b4ccd0107bcf4e8ce081135f2adb345ba3df9a4df5637d3cd9e08b43ba8Virustotal results 21.15% Quakbot
2023-05-17Ykrjm.jsjs fcdda21a712620d2dbecadb236b7ca8d2b6cef444f9848f2ac95622ed210a4e1n/a Quakbot
2023-05-17Ohovgz.jsjs fb5908d59b642acad4cc8e4b40c8003da06b37e422221c358758d820f2c0a53fVirustotal results 23.73% 
2023-05-17Lctdh.jsjs 8f29c702a43f99c1cfc18167ff61035ac4068757aba92e0eb5e9dde5ad72a0cdVirustotal results 31.03% Quakbot
2023-05-17Siwvrdvg.jsjs 0eb9fa07ffbdae465ca7afa7b68b6b38311315046844cd6ac97c9e3b77d5fe99n/a Quakbot
2023-05-17Vfsdko.jsjs 2ac229fd994bdb64a7cde85dae50a0f2f6a3229eed9afc763d5f8d0e9b4f0ef9n/a Quakbot
2023-05-17Inntcv.jsjs a74b08fd8574636c900a77d9d50f0c7d91b058b6a82d501d33a366e1e7c3d343n/a Quakbot
2023-05-17Zyrh.jsjs 351524db3d56c005860ef4fd4537dc2c5861469c3c10e549e1b43c1135c90750n/a Quakbot
2023-05-17Afnklvb.jsjs f0e7d5cb05899616df2135225d017e09422cac28346dcc56e2d33e3608c2a0e6n/a Quakbot
2023-05-17Zvvq.jsjs 2661b1706753c9ec6dd96d86d6d85aebeae08bce2bf5efdb7201f6f040c09a7an/a Quakbot
2023-05-17Ehwz.jsjs 4e86a744bb291642d38947afbc260b86857f84707a386667032c0ae85c50c24an/a Quakbot
2023-05-17Moiw.jsjs 571cb5ffcc14e3e731e7ef4d7a625e47aab8adb029d4f72cbdbb5095c59e7163n/a Quakbot
2023-05-17Dixdmcot.jsjs 84771354c3237cdb8298cd2bbd359d333173eb59c00ee4838b266a517438a96cn/a Quakbot
2023-05-16Qdjfsls.jsjs b056d890009b59a903cc6e288607d3ff5409e7761f1cb53f115205db9e200870n/a Quakbot
2023-05-16Gofdmq.jsjs 1b9586e80384b7d1fadc43fb0749988c8c2eff3e1cff5d4928a095c72b7b864en/a Quakbot