URLhaus Database

You are currently viewing the URLhaus database entry for https://neelikon.com/eatx/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634994
URL: https://neelikon.com/eatx/?1
URL Status:Offline
Host: neelikon.com
Date added:2023-05-16 21:58:10 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116902 created on 2023-05-16 21:59:05 UTC)
Takedown time:2 days, 0 hours, 8 minutes Poor (down since 2023-05-18 22:07:35 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lejmzdy.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Qovwm.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Xxdvv.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Zqffkq.jsjs 42b1426d41e21ea1575d83ddc5ef2f1fd4f30b0511ead37de614c58fb504351dn/a 
2023-05-18Yneezz.jsjs abab065bf35d31ff71f44feed5659074ee381a93862817826b7b884996333700Virustotal results 25.86% Quakbot
2023-05-18Hbrw.jsjs a9f2a0cb2e1331cb0fde62a0318a6e4666f4e283157690f3f7a1059aa73b2f71Virustotal results 30.51% Quakbot
2023-05-18Cexekh.jsjs 42d74e9be0d442e0bbebc6134157922913abc72510b235bfa67b53092757a2f4Virustotal results 30.51% Quakbot
2023-05-18Bwwhoteq.jsjs 79b1f8ec256643dd38b44883fae1a1c46e851db6d07560d38f8cb371756b1fa1n/a Quakbot
2023-05-18Cnbmx.jsjs 73b1e3fe01be0b7a83d8ac43d397530b110d3ece6e3ff93d424b36d0b7336aa8Virustotal results 26.67% Quakbot
2023-05-18Bkchhjm.jsjs 093f4994d50fb15a657ced4731d4109a45ae410dbe91554d201d3ad2c44501acn/a 
2023-05-18Nuihein.jsjs 9487aeedb7473998494f4a53f02cd176e21f14043b6e2e75cff9016c277d0c0en/a Quakbot
2023-05-18Eqqktg.jsjs c9405181760bf1482ac0fcca4034002716ef5a48bacdfd80e3cb5353db6fff56Virustotal results 25.86% Quakbot
2023-05-17Evulbcm.jsjs 5fe1ce92222b0ef2d0fe599c26907689fbeb05acb3c14dcc9cd468d2db479a26n/a Quakbot
2023-05-17Ttgwcse.jsjs 32805d4a1cf5298234803410351824aacdf3ae591f390289a3ae325ad6e77e1en/a Quakbot
2023-05-17Ndubiwcw.jsjs 7b0e64b5b88495d402a11b16ad7776cc5e0d44a07992e8b9cf9c7006a92ac8bcn/a Quakbot
2023-05-17Lpeqizpw.jsjs 4c15dba778afb1200f2c6d840c81c397c3fa416e7e47b19d01800000c0ce6f82n/a Quakbot
2023-05-17Egiev.jsjs c73f356c704556ac74d752c91963fe6a1c7273b77027b218016b83f03ca878eaVirustotal results 25.42% 
2023-05-17Whpnj.jsjs a4d5af2c7491cf9e8c6fc213f49572749af1f591ad0e453bfc3770dd17d884dfVirustotal results 17.24% Quakbot
2023-05-17Uxshxgy.jsjs da4bf3b68417dffef143d4e6c343ee8adb0fc59559ccca0c4ba48cd6e3e1e5f8Virustotal results 25.42% Quakbot
2023-05-17Jhkcpsek.jsjs b243ce7f5b24e6eab35ff99fcc718064f5897388b337460b05226b50e50b7dfen/a Quakbot
2023-05-17Owya.jsjs 4354d95ab4bca50c017bd9924b76993858cd95779d7c2e8df9e46333db74efb8n/a Quakbot
2023-05-17Wjmewnwu.jsjs c9b1270120c5f75d48dc37bd9cdf9899fa44ed7c7b1133668fc92a4b30d88c63n/a Quakbot
2023-05-17Bkgwl.jsjs e72c8086e5382d089bdcf262d6ba0f666f180cde83264d8ef1a3181b5916059cn/a 
2023-05-17Rsiwaf.jsjs 7ca31ffd91f5652cfd89b228be192412ea78c7deca00cbbdb23e0a4b5f0b8bb3n/a Quakbot
2023-05-17Khzfa.jsjs b391c182d00093af281fa5aadf237eb00bca219a83886441533fe1c5691de450n/a Quakbot
2023-05-17Szbqvne.jsjs 8a4bcccaffb669b7d71d5781cf7d22a1c1d781f933bc56f770cbe5bbe08d1b84n/a Quakbot
2023-05-16Mkzrg.jsjs 8ea3782f286a77ca3fc959b3827bc1cd3b1c6449d6515b2bf5b42db5327b7417n/a Quakbot
2023-05-16Yejdot.jsjs 8593006f2125455f9b2328f75dac6fbef453d19f4a2bb4e73e062c4acb88395fn/a Quakbot