URLhaus Database

You are currently viewing the URLhaus database entry for https://rglobalproperties.com/am/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635032
URL: https://rglobalproperties.com/am/?1
URL Status:Offline
Host: rglobalproperties.com
Date added:2023-05-16 21:59:06 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:00:08 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 15 minutes Poor (down since 2023-05-18 21:15:35 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qtvkjvqv.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Qzxmiqg.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Zceulr.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Hrgtsbuw.jsjs 0b89d67c931fe13fdd7836317d3e9fef23ea7080a0da77d3f6505571f09d65a2n/a 
2023-05-18Yprv.jsjs 17ee5a686914f6713574da4e30d7902af9bdfc03eb0173e1143cc97a4fa37b75Virustotal results 24.14% Quakbot
2023-05-18Auznlza.jsjs fab89deda2e8de1afcdf4d43b713652dab42ebcad6b4eddcd3b225188a7e3078n/a Quakbot
2023-05-18Hnreyela.jsjs af1b94948c602627bf551b38dae50d6be3c349f5b15e7fe1d2a792e047809553Virustotal results 28.81% Quakbot
2023-05-18Tidwpzp.jsjs c56be3ec9c7d01ede485ea9edabc332ef3aa01f6ab679c4eb6231e1db79db675Virustotal results 23.73% Quakbot
2023-05-18Wsjkpnud.jsjs e4ec32150d6e87a71d76e7b2f71274e3ac9a2b263e4fec937fbcf4b766731192n/a Quakbot
2023-05-18Nzkxhl.jsjs 534fb18b08176440d03086ec406d8a79bdfaf1488c044a8355d161fd7e521950Virustotal results 25.42% Quakbot
2023-05-18Puuvzld.jsjs 8ef706183443d30910cb1d411aa36e657e86119ff849b6a9edef4125b752bb92Virustotal results 28.07% Quakbot
2023-05-18Znjkb.jsjs 8eec4b2ca78d1d8b62a875c3a6b16a0a9053aeaf65f1e6cca22000629ab71432Virustotal results 27.12% Quakbot
2023-05-18Apwtfdd.jsjs 9ed630b44354fa9a5b12648e092b487dbecee08d6aad53bf5d2695dbea9b9cc6Virustotal results 32.20% Quakbot
2023-05-17Imseiei.jsjs a1f08963f5715bb8830f2ea036c6be1f8a5f34bc8a6bc799c36611f79e54b14dn/a Quakbot
2023-05-17Odkrgy.jsjs 562698d61476d96d6f3b0fd847585b9c5e4d1f9eb96f8153ba577725aa0eb697Virustotal results 27.12% Quakbot
2023-05-17Nligwmam.jsjs 26bcf4ed38ca973b884b3322675bbd0b590533240961f9fd6272fa3e3aeba113Virustotal results 31.03% Quakbot
2023-05-17Rmefx.jsjs 7ef24e8dba41a6e1f91b0d04f772ccc6300b92293dcb30726bd5052c1e2ccca0n/a Quakbot
2023-05-17Codhoqrf.jsjs ec6f55b9c56d3dead8b8490dfbbcccadcdfef62b7d67c671b8d0ee9620f4b74fVirustotal results 16.95% 
2023-05-17Ypmaq.jsjs 817e3087dd09d826cc20a0381d67784b264c51a854134ac760b9219f49d58f0dn/a 
2023-05-17Cyom.jsjs 09f9e4d8ef85ba407416a7d168207db81c2000eabea300624e17d81f58bd0b18n/a Quakbot
2023-05-17Gaetq.jsjs 07d325ade48f67b7d86a967bf6423b41d1a70bdd2c309beb2498b6f75cc9bd81n/a Quakbot
2023-05-17Icqcy.jsjs 7057e97bf0be91bf2780a1f93f7b059fb28dc6c464ecbda63fa351c81455c648n/a Quakbot
2023-05-17Fzvl.jsjs 5fd4d8de191a697280f53350553b87615213197961b0a107f72e527171e88948n/a Quakbot
2023-05-17Aakdako.jsjs 4af402ac5f5b1e6a4152a1f176bc68720c226fddc898d8b908c28ab09d0d89cen/a Quakbot
2023-05-17Gaaeevw.jsjs 29def996c94651698c3aa3aba2586fcd8bb8e9150cb2386f4a7d12858dd4d58fn/a Quakbot
2023-05-17Kqkwwmif.jsjs 1699cc7f2a5a02ed585b2bcebeaf21837e498d0835e6aebddbf06785bfb54a3en/a Quakbot
2023-05-17Azmz.jsjs b29f04fec870ee612ceb9fdbbb7caad8ad3cbfa7b4e7bd9cb069fb4f03e36b19n/a Quakbot
2023-05-16Lvmtq.jsjs 96dac715cba5db57a25b69855f67985a87f31ee55f116e9d11f83620c1e0644en/a Quakbot