URLhaus Database

You are currently viewing the URLhaus database entry for https://mochilasgo.com/aim/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634987
URL: https://mochilasgo.com/aim/?1
URL Status:Offline
Host: mochilasgo.com
Date added:2023-05-16 21:58:09 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:40 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 days, 0 hours, 25 minutes Poor (down since 2023-05-18 22:25:35 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Jyalh.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Hghmjioo.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Mntcu.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Sahvzo.jsjs 13c765308969e5a054ed4ef1349ad4ae58c79d3bdd9937f2a25b388b1e1f9b29n/a 
2023-05-18Lugtc.jsjs 340674eac99b309a0a10a07f5d961e87788e88c4cc2f218da6cd61ccb196deecVirustotal results 11.86% Quakbot
2023-05-18Hujodasy.jsjs fecdae98fff4b89aadb8c35ded8061bdaa126fc12f3fd482cbcecd53246c1c0an/a Quakbot
2023-05-18Vhyjulgm.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-18Yfujy.jsjs 86f81887bb6051cb0f8b8b3d948a6e4bbff1538e986a71386da56590e614f26aVirustotal results 27.59% Quakbot
2023-05-18Wbpj.jsjs 2c91bde6a534aee746616dd47460479f4813dd91fa6b608246e4cbd908aedf83n/a Quakbot
2023-05-18Yijfvw.jsjs c183dc69a6e054260b5800df8cb1bdcf33338ca9f2d92f1b6d2161ca1fa1b850n/a Quakbot
2023-05-18Bckuxc.jsjs d953d8ab979233a6b29a964f031086bd74ed7eb684d99d10f5a881778f4d13b2Virustotal results 27.12% Quakbot
2023-05-18Ybyso.jsjs bc85062a6ed96ba55f83637c5941ebb10dd8734a7486eb2e716a41e21578b347n/a Quakbot
2023-05-18Stwnhhy.jsjs d7c515caf105f46c900f5862443f7dccfef29b7544788a80e4bf47e410fb0106Virustotal results 27.12% 
2023-05-17Tthmnrdy.jsjs f11d7ad43d7a6c6cc716d06a9d41c96156d6ce0dc45d6add8d3039cae526e350Virustotal results 25.86% 
2023-05-17Pqtfkrj.jsjs a18a3c0e37cfc92a00d139f4aebd7996690f4428dea318f028570bf9037d8aban/a 
2023-05-17Xoiftth.jsjs 41a9ac47a4429134ce75e112f1d067da61f8dc65ee77cd9e494c9434cf179f12Virustotal results 30.51% Quakbot
2023-05-17Vitmefzc.jsjs 6341f87ee4bc63114ac2e7899107fa341aafda80e5fa00f00b0f72d89ddc06d9n/a Quakbot
2023-05-17Twbwwte.jsjs 8a9af030d5759e428811a44e1582012c64fdef7059286c4c1693f13566e2d3b1n/a Quakbot
2023-05-17Crqcsoxj.jsjs 3bb38fa6f98d4d9251f3db4a5374a212389305ea2079c93ed01408cb473d434dVirustotal results 15.25% Quakbot
2023-05-17Tacyvcxi.jsjs 2c6c3f6ffb898b9a29cc0a5ec84ccecf30800496946b378d5558f81798278c3an/a Quakbot
2023-05-17Fbiy.jsjs 5ffe664fdbacfc3671675c413145b7f80030ff451b4eb7fc3f1776104c6332ban/a Quakbot
2023-05-17Ijyny.jsjs fed2a6dfbdee6d078b91c6ed65da5dec9e3f8c8f83326bdae9a0060651a426e7n/a Quakbot
2023-05-17Vyddfyg.jsjs 162c1d3b6ae23566499c843fb6933886eaa65649863cc8f57c4c8575ff0c9be1n/a Quakbot
2023-05-17Foub.jsjs 5bb5f99026fd3f924f5ba9565538791ae2ec8d32e97f188cc85b20f5682eb99cn/a Quakbot
2023-05-17Bftprwbd.jsjs 87d15bf99839f9019ceb5725603ba6c877a52625e266338c63646ee51237e9ecn/a Quakbot
2023-05-17Seme.jsjs d2b43df5a6f9227a5b9f1e79b60e9af533e23ac27873dd91477ce8e355e4c476n/a Quakbot
2023-05-17Pmfhfk.jsjs cd7ed767f7656f424cf47307cc8d8452165e69f39cb017cc9aedb17726d81ed3n/a Quakbot
2023-05-16Gqvovhzm.jsjs aec539c9071bbad342d4b1b108a2818017a10513c88e2684d6e140d7475e1f2cn/a Quakbot