URLhaus Database

You are currently viewing the URLhaus database entry for https://mitchelltechnologygroup.com/xm/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635014
URL: https://mitchelltechnologygroup.com/xm/?1
URL Status:Offline
Host: mitchelltechnologygroup.com
Date added:2023-05-16 21:58:13 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 23:07:06 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 42 minutes Poor (down since 2023-05-18 22:49:54 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Aymu.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Mmnwjccs.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Hndj.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Fjzgzsw.jsjs 527e6657ecef7adfff8dd61b201559dbd476eaf09c5f4b1cfc0577750f26f582n/a 
2023-05-18Jqhytd.jsjs 70a531a610e47641bb1c9aa721282178341c6ccae5578f0ba31a38cfc5cad76eVirustotal results 27.12% Quakbot
2023-05-18Ykgy.jsjs 6d5e3d77360658771bba4d35e8dd94a77d30f33a7c30ab86b66e271b54d2a638Virustotal results 20.69% Quakbot
2023-05-18Zwxvmru.jsjs 41d25fd2c9445a58f5ae64b05b6042873508bfb85efe4b1b00c3c1b03c4f930bVirustotal results 27.59% 
2023-05-18Tzmvz.jsjs a93a8bf8a31ec8306c9567bf9a32a827765ff0e798aacba99ea917a481f43f7en/a Quakbot
2023-05-18Zmzzh.jsjs 043c810fd7d77672928841fc44891531ce536c6b4cfb9a4e54529c20b36eecd2Virustotal results 30.51% 
2023-05-18Winv.jsjs 3c39de1cdb595f8d1822395bd3cf9c81743a1b303cf7188cf41f49bf8c0005c7Virustotal results 31.03% Quakbot
2023-05-18Alhwl.jsjs 9e158a8d22dc98e3ae057267f1f3abc2cabc910f829c052269762460d602479aVirustotal results 25.86% Quakbot
2023-05-18Qvsyd.jsjs d1a4226b93ce7e197a1d0a500323d097493998ae6d92816b4793bac2150218f2Virustotal results 27.12% Quakbot
2023-05-17Tiofqrj.jsjs 0c7ba195ded6d8e316021ca662000aef82b48c95dffdd60c2ea37f1849c555b6n/a Quakbot
2023-05-17Ulxtjf.jsjs b896df419a5e1ac8fe67ede2b9594d6252e8dbf87ef64fd093ceacc52a84798fVirustotal results 24.14% Quakbot
2023-05-17Bggkv.jsjs c73f356c704556ac74d752c91963fe6a1c7273b77027b218016b83f03ca878eaVirustotal results 25.42% 
2023-05-17Aqbzrgyu.jsjs 8319c01bce9a24d28eeb4e926938d179f37c880ab2aaa26290056ff5089ceae2Virustotal results 27.12% Quakbot
2023-05-17Bhjv.jsjs 5e30b39e34b262f145f195328ba0967ae018af26240225770cb9bbac24dc377cn/a Quakbot
2023-05-17Uksjsm.jsjs 4df2da0e1a60159c49866a7e3899e305f80766c9bae6b676bf18955d4e2ee8ecn/a Quakbot
2023-05-17Cxjypep.jsjs fcddde4aefcc392bf143eaab986f85fa9fea69d7d232194ecf6c3080b8b60a1fn/a Quakbot
2023-05-17Utxcqr.jsjs 7701415f1b47f3f78168e3820e322c55eb8b2b1391a4607cb0a70c15ffaae996n/a Quakbot
2023-05-17Rtyu.jsjs 39fb66caffd92a5c1c7f0cefedcb4c1bab48d62e52c2c802c0f0717664a7ffccn/a Quakbot
2023-05-17Rxtaz.jsjs 19f7a1bf1f20466d606eecd8f2341cb441794a8899cbfcdc0b6097f81568045an/a Quakbot
2023-05-17Qvamgebr.jsjs 834912faa8592cad47d43b3c91984d68b0ed6970722a115ceb7f95553ceae7f9n/a Quakbot
2023-05-17Wlixaske.jsjs 702ced77d4bdfe17d8ae92099f93411f555e337aeff9770cfbe520504899c141n/a Quakbot
2023-05-17Iuyydrzr.jsjs 39da852fe4026b105a63c68b56631a93e8cf2520a1bb4a7364f5c95a09b17d7cn/a Quakbot
2023-05-16Xsekc.jsjs d1805ed446e86faf776ffa78493d9a5907e0c4a2b641482cf9573955b05c234bn/a Quakbot