URLhaus Database

You are currently viewing the URLhaus database entry for https://msconsultancybd.com/uqm/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634989
URL: https://msconsultancybd.com/uqm/?1
URL Status:Offline
Host: msconsultancybd.com
Date added:2023-05-16 21:58:10 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:39 UTC to sales{at}dfw-datacenter[dot]com)
Takedown time:2 days, 0 hours, 50 minutes Poor (down since 2023-05-18 22:49:56 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Bznvpp.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Aesguh.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Mdjafgbg.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Blbf.jsjs 651d3a1dc113902ae2eda79d58777bd1815d6830da2e21e06efe9ed20d6e810cn/a 
2023-05-18Domdvs.jsjs 0857b5e40844024689620ed0e9d9fbef8b9b295f54e11fba7dd9693f59ce40fdVirustotal results 27.12% Quakbot
2023-05-18Vabu.jsjs 7d4c05f2b21fe02c34ffc3bc7077929482fa7cdbc01c894e2647cf6e38ab20bbn/a Quakbot
2023-05-18Kmdopqg.jsjs ba77ea0ae3afe4582d390d1930a3792bde2ba411df7e3c05ae156306c5cd46e4n/a Quakbot
2023-05-18Dpbdfpo.jsjs f37d3c915b896922eed07327ecc8b944fcab1445d20c02c26c5aab8d91473b45Virustotal results 25.86%Quakbot
2023-05-18Wyvf.jsjs 72b50fe52615ed2facfe5a1517ed75f7ba6d2d98e26968645dd646186fa5fef9Virustotal results 24.14% Quakbot
2023-05-18Iadexbwu.jsjs 4604c9a02925f680aa68df7691aab5b247d61f74fa2c2c261a58ed40e9680327n/a Quakbot
2023-05-18Sziczl.jsjs 0f8aac75339d21d38c89f545a30c35990759d0f0123017fad73ed0c8ce34b51cVirustotal results 27.12% 
2023-05-18Hxsmid.jsjs 8475cb42b6b2c974e37378cf11491570a83f194a37e5ebbc50add4a5677d6d72Virustotal results 25.42% 
2023-05-18Aamjn.jsjs ebe8f7530444ccce930ca2eb9bce9d1a8dc83786f22d231c9b0ecc1b37803d8aVirustotal results 23.73% Quakbot
2023-05-17Uhvjlw.jsjs 17c72916bd400a92cce59ce208e3dc0e55b97f9b3926f0819456072bfb9090efn/a Quakbot
2023-05-17Qnmng.jsjs 817e3087dd09d826cc20a0381d67784b264c51a854134ac760b9219f49d58f0dn/a 
2023-05-17Qknt.jsjs 95f993cc876a8c3aa072647ab634b4ef2df037d739e781cb6f6b4e90ae5d6889Virustotal results 25.86% Quakbot
2023-05-17Exulzosk.jsjs 0259d5d40b143ebaaf60af05f38a325f660c922eb6201a18e664d949c3be13a3n/a Quakbot
2023-05-17Xmktv.jsjs ea84f700c5132b793e8bbc20dd9383bd71e86ffe8be7ec16ec7fd5ada9cfb33en/a 
2023-05-17Ygsvui.jsjs 819e1677a9b83e3e2c5f43d5b2dc0f2f54147bd8257c067505fb818330efc68an/a 
2023-05-17Hqpp.jsjs 621b5cf40077c9b8235e3525da2dea7b28a80029ac3f7ee7477d78c780f4b8c7n/a Quakbot
2023-05-17Subufeb.jsjs b9142696a43f7cc9917c01d7b73c200a9735801ff9b95259668bbe955f6dd8bcn/a Quakbot
2023-05-17Vbgoplqg.jsjs 7b82968f03f2c0b4f11e7b9a05a3dc185d55065463f308c0c842e52d81569ea0n/a Quakbot
2023-05-17Rhaqlnef.jsjs e6a0598dda821f4085c2eb3e011c17e89dc29b8a119737600eca0886de9c0316n/a Quakbot
2023-05-17Itmfhj.jsjs 5d8184f7a85d27ac65717e1e6485b43423b7935a3ae1c4755204a95ac41469b4n/a Quakbot
2023-05-17Vxoujfef.jsjs 2f28929fd87e07d7609ff9b6706885f3526bae23f8d38074152322fd017f6ea5n/a Quakbot
2023-05-17Klcbt.jsjs 88ed297351ce56aa9252ce2d33e91dbfa1e5ace1454da3a5d65a2fa864d45e5an/a Quakbot
2023-05-17Ohenhud.jsjs e2f7f129d36893d7b80419ecd77035e1c510968f9db9f726a2c89b3cd70b1fa6n/a Quakbot
2023-05-16Rcowhbc.jsjs 2e2ab6efc8549da40c61cbb99b69f39436650326c6db759f71b76dcf1977d710n/a Quakbot