URLhaus Database

You are currently viewing the URLhaus database entry for https://peruinkatrips.com/sanu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635039
URL: https://peruinkatrips.com/sanu/?1
URL Status:Offline
Host: peruinkatrips.com
Date added:2023-05-16 21:59:09 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:16 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 23 hours, 12 minutes Poor (down since 2023-05-18 21:13:34 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Grjts.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Vqedtcy.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Kleltkzs.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182en/a 
2023-05-18Bvtavkw.jsjs f37d3c915b896922eed07327ecc8b944fcab1445d20c02c26c5aab8d91473b45Virustotal results 25.86%Quakbot
2023-05-18Yggcxvr.jsjs 53b3144d6c4d4163d5317d32d6bfcc11069a721edc167234c3599a6e2aae5274Virustotal results 25.42% Quakbot
2023-05-18Opdb.jsjs ccdaaebf2ae2ce525ab5ccf2b4d74cf6b58e7d9515c21c0d46e2b8e0709eefb6n/a Quakbot
2023-05-18Sdegrgrk.jsjs 4df2da0e1a60159c49866a7e3899e305f80766c9bae6b676bf18955d4e2ee8ecVirustotal results 15.52% Quakbot
2023-05-18Fhmob.jsjs 91bf97c2e5d25bf79ff22ef99cccd3bdb7aab412d34521e172610b16562203d8n/a Quakbot
2023-05-18Kbdpb.jsjs 399c7eece18438ba4f325cfc3863d0603d1237732a310fa2124a136ff2a335afn/a Quakbot
2023-05-18Wbnj.jsjs 285384a5ccf94492475a9af926ddb24dc621f5b0f19df79f8ed7366ca130d544n/a Quakbot
2023-05-18Esqo.jsjs 905a894ac3b18458a8372c05faec1cd015ea3d7f3a5d248f87684a3062f2ca5fn/a Quakbot
2023-05-18Xpanueg.jsjs a8a8153cceaada2e2ff92961844812b0aed9cd17ebb6700ebca64bc3627c960bVirustotal results 28.81% Quakbot
2023-05-17Dqyvkvi.jsjs ad227c276250c72ebaf4c13e5d960347009d0762b8c2e696a35b36232e0eeff0Virustotal results 27.12% Quakbot
2023-05-17Lyrd.jsjs c5a390d1bf67c2241e5a9cb33cab3e83b41d4319c494c9f15d864cff3015e95dVirustotal results 15.52% Quakbot
2023-05-17Gnirjp.jsjs 13fa98699be69d8a22ee7c59e1a9efe2f504a721757490445465dc8a1de1765en/a 
2023-05-17Yoplnc.jsjs 45a695a6696ee2284f34ef03f76d7192a3829a64f1ae5f5216bfd36983231680n/a Quakbot
2023-05-17Dtqvifc.jsjs 08a4ded15b1b100031a7d4d5816c32a45f5bf29a74bb677f99634db21d3cd646Virustotal results 11.86% 
2023-05-17Akojgb.jsjs 2177d925f10e2cd3a5d175b8e14d8faa7413f6cd18da6fc7832edca35cdb5aadn/a 
2023-05-17Fltkno.jsjs 4aa5d2a8e1f14eda407f7f6020bae48610ad7ecca61519bca8d513c840e454dfn/a Quakbot
2023-05-17Zkkh.jsjs b2fe3390569f2c1a0262e8da4f0c4c7c8960ad149b602d6e9d460b37fb6e00fbn/a Quakbot
2023-05-17Zuextm.jsjs 78ff3ee7dc96e9ba1a1f6db131bcffd1aaef201d47ae9ec61e9b72c8a50853e1n/a Quakbot
2023-05-17Ulcrmsd.jsjs cbcdbf9d6cccd0b99a4844f87acd87a0ba89d8841c585b9206afe48ebd162a58n/a 
2023-05-17Ghgu.jsjs 9c64891e6963322664c6b828ed98ad1c265ffa78b5c75018a7fe474e23f6948dn/a Quakbot
2023-05-17Dljuih.jsjs c7fd0a1183fd762aca152875e5442909cc6ffbfa2d18af3591c1f88bee3bcba8n/a 
2023-05-17Bakfmbm.jsjs c1aa9193de4fdbbb39e83ee8cf96cb3b0593d7d11bb8d28c031bed62f6140483n/a Quakbot
2023-05-16Anfzobyi.jsjs c1f2d338e22ebf83bd18b8ccbe50bc65a14112e484afd3eb68fa9fc6d6362d55n/a Quakbot
2023-05-16Zkrsprr.jsjs 4068a49b9e8143510d8ee6e1608c12c35457e3f9391d3b295511a21a16b975edn/a Quakbot