URLhaus Database

You are currently viewing the URLhaus database entry for https://phillipscr.com/arud/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635027
URL: https://phillipscr.com/arud/?1
URL Status:Offline
Host: phillipscr.com
Date added:2023-05-16 21:59:06 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:16 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 23 hours, 1 minutes Poor (down since 2023-05-18 21:01:12 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Schds.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Qloi.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Hkbn.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Jsvaf.jsjs 80845cdba5f01c2052bae6271f900ce610665a1d59233d4e3922d4c376b2f553n/a 
2023-05-18Daek.jsjs 813efe88246132a445789b21b1536bd94263cd9a8c7623d7b96a9e5ac755d470Virustotal results 31.03% Quakbot
2023-05-18Kfav.jsjs 1bff54d9504766a1b23df7d6c83ffbf3db9ac0d0cc9ded739c34a0f1114f5717Virustotal results 27.12% Quakbot
2023-05-18Zejyapoe.jsjs 60483947f59c4a843833ac5302fae111fb318dafe639770153154f7e01c2afa9n/a 
2023-05-18Tjgqv.jsjs b7aee295279db7ddc9a5aaf2c89b1395f0a2c3ad92cabddcb41b024dbeff9c64Virustotal results 18.64% Quakbot
2023-05-18Exjbqin.jsjs 9f16a38888bf7c130dfc15dff72eda59b2621e7c1048f157a4cf51e9bcb2e280Virustotal results 32.20% Quakbot
2023-05-18Qvmcje.jsjs e5f9fc33236b5ba2988d71e8585b3802d96cde07263ae499ce6ac56cc9db183aVirustotal results 27.12% Quakbot
2023-05-18Bemrsc.jsjs 4fd5f473b0f97c7dcf4a244234c780051bb0e3c316acbb18b7f959a6663c9454Virustotal results 22.41% 
2023-05-17Lyuspzmu.jsjs fc4e17680da39bbf2dfbf388da243c919927a825eca7d8de8a39d74be04968e9Virustotal results 31.03% Quakbot
2023-05-17Rvyqc.jsjs fdf950ea03d008fe87c7f897e464c152d19d8f830013223033ceb1852f37ef5en/a Quakbot
2023-05-17Lwxrio.jsjs abae955795961dc369ba3d41196f2f4238001efcff8a2dc429ababf4821ca7f5Virustotal results 22.41%
2023-05-17Ujzbryd.jsjs 028981687a2254e22ca965537b4ed290d1dca3b0b682da744c55d1763c98565aVirustotal results 32.20% Quakbot
2023-05-17Stuglkoe.jsjs e29a41a9d60625c8b7ab2e66896cd279af26a9abe095095e8f71d39a518717dbn/a 
2023-05-17Ckhhzmqn.jsjs 5e1581b1da5a05a5baee064cf15334c7199e5808fcb9b16decf62e6cb66940c5Virustotal results 32.20% Quakbot
2023-05-17Foyoc.jsjs 1539b3e778af6f644e932c0910705fec144fe2bbef2f8df241b0d4bb821d0fc5n/a 
2023-05-17Woheshe.jsjs 81d46bf6cc71d927906bc2a9ae29103ed6a1d3f01599e9736dd016267c874521n/a Quakbot
2023-05-17Vdjw.jsjs 86452f341bcf99a162bc34f7d02196a5deed2cd695959a4db7c611a5e8408251n/a Quakbot
2023-05-17Tfobp.jsjs 4b663624f858d07543044fd19bff791ce2f3ec0ce74a73e61350c6952a635ed4n/a 
2023-05-17Zxcive.jsjs bff75227676de9a54a3119bb29a9bb8fb032798182664f20f107c25970b9157cn/a 
2023-05-17Xttrg.jsjs 58de8659a709f46b0bc2d77669925b89509d7ac41ba265c0e62343bb075d1652n/a Quakbot
2023-05-17Uvsedneg.jsjs 9cf1ba677fdc547f7742651a1ba4b18e250d704b2a47c10b83c062a6ed066e1dn/a Quakbot
2023-05-17Uvuwb.jsjs aaa68a731715e3dcc12254dba10a2e9ef74664587d690d3040d78ca4c4474a37n/a Quakbot
2023-05-17Gjhe.jsjs d2750facc98780ee51150e049d392a3d57d1f9b6a92497dc27ae8699c1824c7fn/a 
2023-05-16Dmhmve.jsjs 9e6ce788f650e2659dfe2157b0c0b04b9bce76bfa40386d4bb805db3942ada5fn/a