URLhaus Database

You are currently viewing the URLhaus database entry for https://msconsultancybd.com/muau/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634986
URL: https://msconsultancybd.com/muau/?1
URL Status:Offline
Host: msconsultancybd.com
Date added:2023-05-16 21:58:09 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:39 UTC to sales{at}dfw-datacenter[dot]com)
Takedown time:1 day, 23 hours, 14 minutes Poor (down since 2023-05-18 21:14:07 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ndcoqvke.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Ywqwjes.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Siptc.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Idjechq.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021an/a 
2023-05-18Rowpcwp.jsjs f51bc0d7dd86e4e6db698538eca1063e4e4936ee3f57c669e347f143576749d9Virustotal results 30.51% Quakbot
2023-05-18Ahpls.jsjs 2971e245d875fcb96bbbbcff59e1a34e0490ae85f5e8abd688b28772bca0b30fVirustotal results 34.48% Quakbot
2023-05-18Ywqcccj.jsjs 42d74e9be0d442e0bbebc6134157922913abc72510b235bfa67b53092757a2f4Virustotal results 30.51% Quakbot
2023-05-18Dzqaoafj.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-18Bsmtkzp.jsjs 67ff580532af15d6457fe1b6aa59886c46bd5c72906c86b58aae1e7aab70fa3dVirustotal results 25.42% Quakbot
2023-05-18Jyeo.jsjs 4ca00c819ac67574145c0664985afbfd757621b4809ec157f14d22108aeacf8dn/a 
2023-05-18Rjjo.jsjs 3938ff8a3f26ca0c121f461afcbf7394844e31d1fb9e68757fd98de2a4b3238bVirustotal results 23.08% 
2023-05-18Xjxs.jsjs 3bc2c76bd30c4f67c56425ecd3201a7bd43655778be5fee4b7a2f72478c57d5fVirustotal results 26.67% Quakbot
2023-05-18Xdtxwpwk.jsjs e78861a712a577b61558f7ea9878b91e974692081e5daa5f02dcb5ff1cdc359aVirustotal results 32.20% Quakbot
2023-05-17Gelaw.jsjs 27544c60ff36a51e0dae2573402a63de5c6ae28c1c7160377a0d3787272d74bbn/a Quakbot
2023-05-17Lpulgkmv.jsjs 4ade6f7d7cfcd03dbffdfe401ed93fa601500252c858fa6010e54b0587fa0249Virustotal results 27.12% Quakbot
2023-05-17Islp.jsjs ac2f114a6bac8df9444849169360217c9656b866153cfc42dc444cbc6b7b6e35Virustotal results 15.25% Quakbot
2023-05-17Vccg.jsjs 0eb9fa07ffbdae465ca7afa7b68b6b38311315046844cd6ac97c9e3b77d5fe99n/a Quakbot
2023-05-17Mnqhj.jsjs ced3c62c0b0eb34cebf34dbcc0ee8a52ffec9388cc383952b09c7aa421199a79n/a Quakbot
2023-05-17Pwol.jsjs 1c8c07d6d5454652a85d1673775e071cb4068ca92c83d2e45e4cf830d85e56b7n/a Quakbot
2023-05-17Woxd.jsjs 6bf7410f1b32c7fad44030961607fb13ec400a2a008f5817485ba84c5c297175n/a Quakbot
2023-05-17Vhriv.jsjs 53a138ff6ab5c7a849fecb4b86563c926f18e90bae706a72a64ef2dac8957638n/a Quakbot
2023-05-17Eikbqe.jsjs 8ed45e3b34d27061f9998f9ea0ea53727c1cccda9eaead429dbd39451ce35e95n/a 
2023-05-17Stms.jsjs 0523f2897d8a475d53590da46d51de1850b62d6d5267a5a0b3060af8165ffc11n/a Quakbot
2023-05-17Yzhhi.jsjs d5b5afb6a46ce78974fe1e5125befb578524651ea0ed224b46f8754b9825fff2n/a Quakbot
2023-05-17Eubxde.jsjs 4355f60c6d4f81973a6fd5e3dd9c83a526249603e3d8bd42d42a7e4a2e19c1c1n/a Quakbot
2023-05-17Hbvdcv.jsjs 4e49a6f500c971f3c22441ef60ac8305bf61c78634cc7e97b5a1430ee6a2d49en/a 
2023-05-16Mjgrr.jsjs d722da13d7a710dac7c9e95bb40cf8297c27f1a6579bc795915b7d778e812569n/a Quakbot
2023-05-16Enddw.jsjs 4031450b42e0ba3398f44893df2ff89ae7eb4ccd49c65ec1be3015924a89b8a6n/a Quakbot