URLhaus Database

You are currently viewing the URLhaus database entry for https://mitchelltechnologygroup.com/esi/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635016
URL: https://mitchelltechnologygroup.com/esi/?1
URL Status:Offline
Host: mitchelltechnologygroup.com
Date added:2023-05-16 21:58:16 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 23:07:06 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 28 minutes Poor (down since 2023-05-18 22:35:21 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uwmzcs.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Aajrpe.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Wvklfzph.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780n/a 
2023-05-18Cndjal.jsjs a7a7249194b741b44bab1befd74e783ba57af2f211b597961892dcbe975544c2Virustotal results 30.51% Quakbot
2023-05-18Tbtla.jsjs 3833419abb83fe2369255a23b3fa983e65047ca005c0dee0d772efbdbf8ee75fn/a Quakbot
2023-05-18Ssbrmev.jsjs 6c9b5539e5f1f1b4e1d609c95278f2b4bd4386f4efc315a332648f1467d2b94aVirustotal results 23.73% Quakbot
2023-05-18Nurids.jsjs c5b4c29787160ccb71f79ff6637aeac99008ef606c71a4b14629e1281f03f74aVirustotal results 22.22% 
2023-05-18Vqzy.jsjs 8ee5d86b74cd803753d211be4c64578d8d39e7dd487d114bdbe044505063bb7en/a Quakbot
2023-05-18Yhrvxr.jsjs e4e514b57ab086485b47e1413c71a7e9bebc8c84c6615f90bf252d04c98fb5ebn/a Quakbot
2023-05-18Nmkbxi.jsjs 5b903308829f5c7410c0e53ec748a05a9e2205f4400bf2941199cf2223c0e1f7n/a Quakbot
2023-05-18Ngpjve.jsjs bb118ed7175733d7b31163818a3948e5e35d0e3ab3627a549e93cf6afa196585Virustotal results 29.31% 
2023-05-17Dexv.jsjs 266bfb248bbfb5fafc879d0a26c731499ccb3de4c57b64ce4b3a3fc6f836b93bVirustotal results 25.42% Quakbot
2023-05-17Zslwtft.jsjs 8deae0dc00f63d06da4b8491f06c909682b192af1c7ae4467703241c34a509ebn/a Quakbot
2023-05-17Mmbt.jsjs 92541d594f60bdb46e24073e3720e0deb32a8bb5a4409a44b650b790dbeda309n/a Quakbot
2023-05-17Uzpqbe.jsjs 3a16d7765c95e4f1c085fb18814d67ba3d65e6bf93e38d064ef74c1f9d15ac83n/a Quakbot
2023-05-17Qkks.jsjs 8a1f226245e5f15e87409d617437e6d102c8267d28d1bdb3f198a89620b090edVirustotal results 26.67% Quakbot
2023-05-17Wfcrgb.jsjs 6e98b0ad9b6fe81e7dde4a5e76cddfdc25b19695ca702e4faf95f45dfc5a65e4n/a 
2023-05-17Gdgx.jsjs c11631875df89e8d792439c8e9f573ebf097e4bc4926ace66626297639e4bf74n/a 
2023-05-17Kgdqiqj.jsjs b45fa98328f6170801cd88be88f4ac670f2266e2ed383e78f37fdd5d860dc695n/a Quakbot
2023-05-17Jpxplxt.jsjs 894bf2733eb257098c0cfc595061d0bb3a432a502c80971471cedcd4404c9d03n/a Quakbot
2023-05-17Gdbp.jsjs 8c8d05c98b694ef0f491417a07bf58f2efe5956d056db07af06fa1564b2b0f8bn/a Quakbot
2023-05-17Hsksatar.jsjs 38f39c92a305b7210c196db76545adc6bb7494dd075dd1358c0cf582b1a079d4n/a Quakbot
2023-05-17Iimhpg.jsjs d7550d516f82b0d7d93303c8ecf0cae92c13ca9401a9223278177fa6c230fbf3n/a Quakbot
2023-05-17Jozkqlb.jsjs 51ae1a36d91be6f071e4414be5fd21485d53af9137d2026d7706b80640335518n/a Quakbot
2023-05-16Rpkoysb.jsjs fab2927d17d98fc11405141e4a81b66356bc2e1a6747e00070941dffc0cc5bd9n/a Quakbot
2023-05-16Cdxzg.jsjs eddcddff614a5188b72fbc13f1e5b66058cd87d921852879c37a571793e2359dn/a Quakbot