URLhaus Database

You are currently viewing the URLhaus database entry for https://mel-gaynor.com/aa/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634991
URL: https://mel-gaynor.com/aa/?1
URL Status:Offline
Host: mel-gaynor.com
Date added:2023-05-16 21:58:10 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:42 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 0 minutes Poor (down since 2023-05-18 21:00:13 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Jntyotv.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Anbvqu.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Rimvizgm.jsjs 728fff01fd5cfc2aa04a975ec479d54d218769db552496ae89c1989f2eeaec5dn/a 
2023-05-18Lplwz.jsjs 8a9af030d5759e428811a44e1582012c64fdef7059286c4c1693f13566e2d3b1n/a Quakbot
2023-05-18Swfybj.jsjs e21d7ce5a24617b4a823482fea8b703cee1f434028f5ee807b3d77bcb4197988Virustotal results 14.29% Quakbot
2023-05-18Gciscrhm.jsjs 16fe8055701bf9e829e70c4811b31fc75aec4d03582697ab493fd530e84ac6cdn/a Quakbot
2023-05-18Qrvt.jsjs b7aee295279db7ddc9a5aaf2c89b1395f0a2c3ad92cabddcb41b024dbeff9c64Virustotal results 18.64% Quakbot
2023-05-18Daeokwx.jsjs 8116e7914df0a4fae9adad12da668660206754557fac016131c53fcd305d537fVirustotal results 32.69% Quakbot
2023-05-18Irtk.jsjs ef903a00f557175fbe1af9263796fbdaad81dc6578e948729821675219196f43n/a Quakbot
2023-05-18Gtbqfrie.jsjs 1226b64c5cdc915647f5412f5ca66ffeb7ac2c6e7787e3f38195da88b68ca12en/a Quakbot
2023-05-18Nmqce.jsjs c5b4c29787160ccb71f79ff6637aeac99008ef606c71a4b14629e1281f03f74aVirustotal results 22.22% 
2023-05-18Dsfze.jsjs 992ec3c1bccb3793a6ae36e909056122ef9e442c16c17bcf9d771c90b85ee980Virustotal results 22.00% Quakbot
2023-05-17Xzzqkdud.jsjs 683503e1ee6accf36b4e270156fa48982aeb9619157f07c35c1dbbfeb8a43e7dVirustotal results 29.31% Quakbot
2023-05-17Oyeuc.jsjs 0692b014bee9b6b1a01cd4fcf3293e88388f98fb01460d6ffd2b3415d5de9779n/a Quakbot
2023-05-17Kvlpi.jsjs fecdae98fff4b89aadb8c35ded8061bdaa126fc12f3fd482cbcecd53246c1c0an/a Quakbot
2023-05-17Uedod.jsjs 41a9ac47a4429134ce75e112f1d067da61f8dc65ee77cd9e494c9434cf179f12Virustotal results 30.51% Quakbot
2023-05-17Ebiwpbm.jsjs e6823880248255f28dad73af6553cfbae133b6df9f78eff124a379d793265ac2Virustotal results 25.42% Quakbot
2023-05-17Luxnjmak.jsjs 9fb9192d902b2bec0253263ac7de12696284a3203d04c735faf491c94c94ed32n/a Quakbot
2023-05-17Pycwefkd.jsjs 26e8f5245d3928df93af31946f3ff6dcf2291861ef4835e6b23e145cfcf9f8d5n/a 
2023-05-17Icsb.jsjs 330c457ccf4dd994e7e7e44f2fba102420a09726b3d61752f9cb5d35428ab7bdn/a Quakbot
2023-05-17Jejq.jsjs 97fb77aeb721d4c9de32beb60e1351386ecbd456b52815ff26fb647ace042270n/a Quakbot
2023-05-17Mhzvt.jsjs d705d72611b72ecde457882adb7a95036eafaec2cf0680b727207db6ff7a76c1n/a Quakbot
2023-05-17Whkdrxug.jsjs b1441f430f0d98b6c8f022f35dfb99a9b128ed4538ae8c3140d882840889dd5an/a Quakbot
2023-05-17Bfjmtc.jsjs 53d85c850ffacc2c92339e4fbd14efd09518444dcbc561a1cf6cda6fd4d1c2a9n/a Quakbot
2023-05-16Vwelts.jsjs 39f47fbc0ffba427c798db735ea7839f8e9165fcd85e674c3ce3c87539e7b1d3n/a Quakbot
2023-05-16Dwvqcwu.jsjs 6aa51c79865abec68965f6bad01a20af5fbf03113862ad97f97db4caf33a1bb8n/a Quakbot