URLhaus Database

You are currently viewing the URLhaus database entry for https://ortopediawong.com/ifoi/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634984
URL: https://ortopediawong.com/ifoi/?1
URL Status:Offline
Host: ortopediawong.com
Date added:2023-05-16 21:58:08 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:38 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 5 minutes Poor (down since 2023-05-18 21:05:14 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ykcagq.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Myjb.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Xvbm.jsjs 235f17997701ae3e810586b488566954071192731259716ff1377fdfa823d85bn/a 
2023-05-18Kfjwa.jsjs 57d0f159c2157b3d1fe724a568194591ac1d7e93f5493edf11eef0722a08431cn/a 
2023-05-18Flbtarmn.jsjs 0901cf7055bc662e98c048f651a2daa00fc1cec5bc745c6a25f315d5c31dc4dfVirustotal results 25.42% Quakbot
2023-05-18Tcof.jsjs 90854b60ab6b30c83f8839a6d1977dc7968771625bc4a6751d30fa1ff505912bVirustotal results 27.12% Quakbot
2023-05-18Sttqy.jsjs f95ae26c9bf7ecb6970afb88bfa12c71eafd8b35160d2c1658e57d36ea915477Virustotal results 29.31% Quakbot
2023-05-18Egcshgs.jsjs dfa59aec9d3aea04d54bc6bcacf0f7a1fc618f9981bc4a0955947134999d2ae9n/a Quakbot
2023-05-18Nvbcmkl.jsjs ff50e9d6bada1c148165cd94d8242cd7c0651692a508bbec763046c0ad17be90Virustotal results 32.20% Quakbot
2023-05-18Plwkv.jsjs f33a199b902aff95c3dede5cbfe632298042593120c23bc925987f2dcdcfce53n/a Quakbot
2023-05-18Puqhj.jsjs 0f979704b112aec8ec69c28f0075d45f2ed1aa14ddaa3effca523aaba13f0a6fVirustotal results 25.86% Quakbot
2023-05-17Bceyxym.jsjs 26a9ccdd2cb5bd68aea8b06532a4945f8f6585f5ee8e03fd64c7dd7ba9bde535Virustotal results 25.86% Quakbot
2023-05-17Nslcwzsl.jsjs 47f14a8b9c04f43e700eff818ff6490f28ae0bcba08118d1af9f0b06c96779a1Virustotal results 29.31% 
2023-05-17Fjkt.jsjs 05dab37be019900d575f8a51485f2baecb4fe212712970c486fb711a173c6290n/a Quakbot
2023-05-17Nsfixi.jsjs 456c54257858cdc9347b6b71444659a256ae3a000dc1c82298d0fc65ba890687n/a Quakbot
2023-05-17Ifpu.jsjs 0c7c96dd589f0bc1676f7af1371bc70cbf50d310293d070ff8e1fef3df4533f9Virustotal results 24.14% 
2023-05-17Figfwj.jsjs a7559adb58fb8ca343a880d3a323c7307621cf7e95fee410922b0ee0d24d8bc7n/a Quakbot
2023-05-17Wfzxbbh.jsjs 8eec4b2ca78d1d8b62a875c3a6b16a0a9053aeaf65f1e6cca22000629ab71432Virustotal results 27.12% Quakbot
2023-05-17Ceopijap.jsjs 92f7851626033d44d80f0eedba66cee17a4065b9d28f58586c35aefe9b04e5ecn/a Quakbot
2023-05-17Nvikizg.jsjs a2bc3351a702b0f85a17e0dcfefbcdcbb82f36a8d4f8bb46254f643b64e1daf1n/a Quakbot
2023-05-17Sogkzixs.jsjs ea662846caf63dbc1e41ea9c9ee3a3764860c190644c59b6f98d762d1ab00244n/a Quakbot
2023-05-17Xsqv.jsjs 8d6de681c9c8a7f37eef27324d1597999d1ba98840b825a595b34f32d7edeaafn/a Quakbot
2023-05-17Vjtw.jsjs e45ea01efe4fe71f6782db98fa9bf0fb77f494994fb41ee973bbe1fb6caef4e1n/a Quakbot
2023-05-17Fhnvg.jsjs 41fec664421d9400de16cb79b0388266f4e31d17be17a1af71fc31b933220482n/a Quakbot
2023-05-17Lozejn.jsjs 8703ff7e8b92919ec0c852b628a37ebfddcd209dca296a0167568d03826e247bn/a Quakbot
2023-05-16Ihuvwkm.jsjs 23ae389257ccc2bab1487a9287241fbbb943ec232d701f1730a35f801d9a3b9dn/a Quakbot
2023-05-16Yuijsu.jsjs 6984c72e93db78d110c6591337be7f3aeeb4cc9221e2ba8b92cb5874377b784en/a Quakbot