URLhaus Database

You are currently viewing the URLhaus database entry for https://newsvks.com/em/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634996
URL: https://newsvks.com/em/?1
URL Status:Offline
Host: newsvks.com
Date added:2023-05-16 21:58:10 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:41 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 16 minutes Poor (down since 2023-05-18 21:16:28 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Pwubtph.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Xlbhqfxy.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Zayxe.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Mzgb.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Cewhqy.jsjs 33b3b33a7711fe42208255ce8fdfdbbd2ee12a048f2c94466ef6b8c8f1beab0bn/a 
2023-05-18Znotchug.jsjs 0b26bdb33f82264e6ee139e028f16f756cf3c276a5c8fdc923aa5d5e2e385872Virustotal results 24.14% Quakbot
2023-05-18Yvnx.jsjs 03de8856a9267b9e96c1454bd5a13ff8d068076ae6a1b7ca1984367997fa981en/a Quakbot
2023-05-18Qsdhrfz.jsjs 649828b67fb96d9addc5f4c9518dfd03c7eaef5dfe3afd081708297f2d160360Virustotal results 25.42% Quakbot
2023-05-18Mhmzfyr.jsjs 5e580c21deb2f7d63ad49462e90d33c85c35e0b2c3f49ffeb5363cd11e8e9ea6n/a 
2023-05-18Wtlmts.jsjs c183dc69a6e054260b5800df8cb1bdcf33338ca9f2d92f1b6d2161ca1fa1b850n/a Quakbot
2023-05-18Okzj.jsjs c3b7288bc652fda94fb09ac95870f66d2e355b6637b09d5c9fd1b7d64d660a52Virustotal results 25.86% 
2023-05-18Buyl.jsjs 68e8f2f3d6612aa52ea6f93813be80d9984f0626bfb504047a29018c7e7748a5Virustotal results 27.12% Quakbot
2023-05-18Serh.jsjs ce5efda576bdfd577cb85bba27c1785787f37d30869878530f7249504d45cf69n/a Quakbot
2023-05-17Uhvw.jsjs d4048bb4d8d517078d21db74a0238b8f0696dbad0bfb9cecbe0dad5e3a89bb47Virustotal results 30.51% Quakbot
2023-05-17Cbck.jsjs 4779dbaf4f01d866b1dd6a2cdeb855c53a82951952ba41e9af73be849bc9116bn/a Quakbot
2023-05-17Lhatodh.jsjs 44d23f66a1f4b2d201da3bd9764d30d67431194d1ffbbc0ee587ea63d892dee1n/a Quakbot
2023-05-17Myybvqi.jsjs c28a0689fa744ad9aa6b9113d992a9fc9d303cf30f2b622975fb5e9a82ac02e6Virustotal results 27.12% Quakbot
2023-05-17Ksgydv.jsjs 3c65c87cf0e371c576074e364d5d415f782faa5f2381909a0cd1d6d3e16b21a3n/a Quakbot
2023-05-17Hyqtzayb.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-17Sagw.jsjs 076515d52f5219c37701ac4b38e72e4f6a809dffce463343615c3fb079c9ec89n/a Quakbot
2023-05-17Iyperia.jsjs bd902336aa7066dfba330ae24ecffe4a4b6498a94ad2df180478f971c6df3b2dn/a Quakbot
2023-05-17Mgowh.jsjs 8d53abd17b74a7508884f8ff9486cc450234cb88feff1c783268b69bbb5f7d8bn/a Quakbot
2023-05-17Fndxk.jsjs 395d3671eea0503fc9623ba2e49781b84dcef78cc269104048c6fe53559473acn/a Quakbot
2023-05-17Jrykljt.jsjs 9767f548fcf8acbf03fd414d18a47264b746d4b3f39f842b2ac6072368f8ea20n/a Quakbot
2023-05-17Gcpumant.jsjs 39bdd81c89837ec9dfc88b9a581d35846fcf1a0f25b4fa0b3be31b6b88819d8en/a Quakbot
2023-05-17Qpwrze.jsjs 7ed733080eb58209bd9bea643511c39f4e60d6a470221380eb366704b6528a08n/a Quakbot
2023-05-16Kybkikkd.jsjs 9a5890da70b9f039072ca882f1034a742711435f98547e48bfbc41bad5d00c20n/a Quakbot
2023-05-16Lbun.jsjs 538809fd2840c514dd34620211ce27c34230978fcd06b9378164bb55f2c7fabfn/a Quakbot