URLhaus Database

You are currently viewing the URLhaus database entry for https://salmanpoultry.com/er/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635036
URL: https://salmanpoultry.com/er/?1
URL Status:Offline
Host: salmanpoultry.com
Date added:2023-05-16 21:59:08 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:00:13 UTC to sales{at}dfw-datacenter[dot]com)
Takedown time:1 day, 23 hours, 13 minutes Poor (down since 2023-05-18 21:14:03 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Eubygw.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Llwqo.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Izcjl.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Fwhe.jsjs 9b039abcf81fe24f4c5cac3fda3acae1fb6a1f23a6e212fd7ce8ff697a3468fcn/a 
2023-05-18Zxoipf.jsjs 83ac5e2e7a5679355f46ab7791a480cb6a18aa3e86331d062bfc7360a5c060c3n/a 
2023-05-18Jnyiil.jsjs b11ddd3e32db780631dee2546f8eb8498cf1976976b4f9b6229279881aff3e12n/a Quakbot
2023-05-18Yewhlfvu.jsjs f39cee789a4050e31f3f61e2dae48c0b5328d480424a439ba3c06fdf7d12ba43Virustotal results 29.31% 
2023-05-18Sgyid.jsjs d7ee80c4c9f9a041e63b9e4a454dfa6c60dcb7fdd18ca658f2f92fc97f61d766Virustotal results 22.81% Quakbot
2023-05-18Hhyepv.jsjs abab065bf35d31ff71f44feed5659074ee381a93862817826b7b884996333700Virustotal results 25.86% Quakbot
2023-05-18Ualh.jsjs 42d74e9be0d442e0bbebc6134157922913abc72510b235bfa67b53092757a2f4Virustotal results 30.51% Quakbot
2023-05-18Hwric.jsjs f14437be247480b6af38f3ccdd4ba46e6e55eb7b3d706b8df711f63558b8703fn/a 
2023-05-18Lutylg.jsjs 7c13bc2d2d42fdea47cb32e74e359fa9939073a81098e801e04a6daaee5e9ff3n/a Quakbot
2023-05-17Shimmuwr.jsjs af1b94948c602627bf551b38dae50d6be3c349f5b15e7fe1d2a792e047809553Virustotal results 28.81% Quakbot
2023-05-17Gfvhxx.jsjs 502aa2d56dbba3e18971b863336aff4b696a67a0935ca0cc3d9186a3c2c8550bVirustotal results 28.57% Quakbot
2023-05-17Keufugu.jsjs 906e50a48250213ff6fa64b72219e204e4f47e919757a5b1214a5e7682a44da1n/a 
2023-05-17Xcmbqhl.jsjs 9079446bd4c7bd26e207e6897766f15bb65c2e6bd4802d253ec23072dff72e4fVirustotal results 27.12% 
2023-05-17Dixklelo.jsjs 5c2f413b69f9b93e5bf828d8c4219af88afdfc9d6fc5d04d749815dc66cd664bn/a Quakbot
2023-05-17Kbrjz.jsjs 16cf6bcb57e5b6fbd88357c73a7c2e1fea2c60e1facf1122d4f6d9ef672f908cn/a Quakbot
2023-05-17Warwutm.jsjs 3c65c87cf0e371c576074e364d5d415f782faa5f2381909a0cd1d6d3e16b21a3n/a Quakbot
2023-05-17Akvlq.jsjs c66769c1beccde8a71bc20172ba3978dfa20fa8e27c21976b94c10327af6d4can/a Quakbot
2023-05-17Eylziijk.jsjs b3ea9f0d7fbb997384938d0d26f7124961d0120b29be84607168bcbef2a2973dn/a Quakbot
2023-05-17Yrscmaaj.jsjs bce0a963e19f2e12362026286b7c0634a66b845856f08adac3696606464ba114n/a Quakbot
2023-05-17Vsxuykbm.jsjs de73c417a4524f2855875e4d881d1a9c82a7fe779beb57fc962dfcffeee5162en/a Quakbot
2023-05-17Ztdevndc.jsjs 566e0d0e74c654d0802b0561d6c07dd65cecf13fd41baa3fc7202b2a427fff67n/a Quakbot
2023-05-17Mqyyx.jsjs 8abcd8963a0687e38ad0a4efe03a9d7a493d5785c63f9805060e6ef07162d9abn/a 
2023-05-17Ooladxyd.jsjs 7c2a0dd9fb5049cd3af0fab9fe8743f2502b362f081152e16df86490b442098cn/a Quakbot
2023-05-17Yeaxgi.jsjs e89cb9e121bd9cf9873888f58aff8ede757f1ba01139508c9ab5de5c7f89b9fcn/a Quakbot
2023-05-16Zcot.jsjs e24603abd6845c50ae154140792d5abfc00b6df6cd23c9d1cd2d48cb342ea558n/a