URLhaus Database

You are currently viewing the URLhaus database entry for https://mywellu.com/siq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635006
URL: https://mywellu.com/siq/?1
URL Status:Offline
Host: mywellu.com
Date added:2023-05-16 21:58:11 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:51 UTC to abuse{at}namecheap[dot]com)
Takedown time:2 days, 0 hours, 53 minutes Poor (down since 2023-05-18 22:53:37 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Mtjwhm.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Mugdgswu.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Qlta.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Kgprgq.jsjs f94d75af95e8a24ddb8baae3ce75c7c145094845cd97a91a8d4975693e18d00en/a 
2023-05-18Oyhpxdae.jsjs 356497f781814842756d631b841bd2962b7aba15e1e749956f57352ecf4e24bbVirustotal results 25.86% 
2023-05-18Cdphva.jsjs be782f3af4554ce0188bf903632e461191f0020d22f70c2760c1f9d32b21bfban/a 
2023-05-18Kuvm.jsjs 1c70b83f5b4051ac542278897c3b02f334291507f01f685e95893c574241e6b2n/a Quakbot
2023-05-18Dmfjqer.jsjs 26a9ccdd2cb5bd68aea8b06532a4945f8f6585f5ee8e03fd64c7dd7ba9bde535Virustotal results 25.86% Quakbot
2023-05-18Afkysu.jsjs 93492712919e0adee85ebe16363f99eb8fdbfe7f055f8645bf21322ce803cc13n/a Quakbot
2023-05-18Vtjf.jsjs d1a92330c8f58a18b81d7ff1a9ea348b205fda7b106c31a2d1e09764a4557fa0n/a Quakbot
2023-05-18Zxnojuh.jsjs dcb4d36d51f163518e7ef97ffd77d55e49a72dc3b351a6e4051187b5361ecf7fn/a Quakbot
2023-05-18Sagsf.jsjs 9aa3958dd376fcd792957165b53999bc05bdb411a0ea61e30b7787e1a7cdfbf0n/a Quakbot
2023-05-17Zgymarbh.jsjs b89d6433da85e8b53b60dd8f31aa096c923d9b4fb337c03d3b381482ef280974n/a Quakbot
2023-05-17Xqwi.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-17Fffwgv.jsjs 6e988a313f3e3723e109adec17cbf1513010e50c972114a245ebf3ed743e84bdVirustotal results 24.14% Quakbot
2023-05-17Bypltf.jsjs 6d9b8f4761b3d2b4e1c031cece4e6ae593e6a9e7de18a01dd28c1235bf7900d7n/a Quakbot
2023-05-17Ujqdd.jsjs b0be9915846a032654d7a5cdc2488d13fd892ca71f707d67ef917a7ed79bd43fn/a 
2023-05-17Wkxigang.jsjs 72c9727d22512473f4aa27d93e0c15ae33a95784d9804b057275d0d7d8b0a361Virustotal results 8.62% Quakbot
2023-05-17Dhljc.jsjs f0071ab8efac63f43a57e5ce10cebfd8f2d18f0b8df63002a484d4acdc24b4dfn/a Quakbot
2023-05-17Lqffbssy.jsjs c71b67adb0d77f0aab933b0b14591fd578f57849d2a042b446847044075305a8n/a Quakbot
2023-05-17Sfdoivfj.jsjs ee5b8f32922b28223c8f55e2a735df2ab24f1758138d23da4928267f6ac86cedn/a Quakbot
2023-05-17Hzjny.jsjs 53ffd6079af983d8c05e469acdebf9bbf31b74b92747be742a383d9e50194c81n/a 
2023-05-17Cawovb.jsjs 2fb5b08f894413c8fc48e7d9d6d6c902758b2836f89bc4ea974ae46d74c5c1f4n/a Quakbot
2023-05-17Wcbaswso.jsjs 449e964bd936476201b1b4b85b603454efc44e15f07f3565b9bc67a1180f0b6dn/a Quakbot
2023-05-17Zzzqf.jsjs 79b994bbbed7391f5cd3184c10e1c1ff13b4fb41556fac1eb6a7adc202f04bc5n/a Quakbot
2023-05-17Udnxzw.jsjs b50bc7530b182993f1502aab0ff83d9ee76aaf0a9e82fbd7e33cda65499856d8n/a Quakbot
2023-05-17Gaxrft.jsjs 27b62ba17c851793fa33d64f9d1128430651678d2dae44d14014215420c8a800n/a Quakbot
2023-05-16Wgkagdxc.jsjs ef7aa7bb2e19940675d5f2773cb007c4990fdaeb19fe21cf9a56f79af1e84b01n/a Quakbot