URLhaus Database

You are currently viewing the URLhaus database entry for https://redcloudexploration.com/ol/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635043
URL: https://redcloudexploration.com/ol/?1
URL Status:Offline
Host: redcloudexploration.com
Date added:2023-05-16 21:59:09 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:20 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 17 minutes Poor (down since 2023-05-18 21:18:29 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Snxunkgw.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Qouwmxbf.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Vzygjfz.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Iyzh.jsjs d51e626fb3ae0d26ef9de767874a563413c3bb97677ac9d77e10db793ffc2812n/a 
2023-05-18Hogkuyw.jsjs 3b3714312b9a47880e50308268338b4ce72011e082b2bb4bd94f2fbe7f738e56Virustotal results 26.79% Quakbot
2023-05-18Rxbsgzg.jsjs fd0ca1aeb929c31a64a1ec9c5027c0c2c644161a6fe7faacf6ea8ec30ca8806an/a Quakbot
2023-05-18Nuxat.jsjs 72495f905e654ea365738e7e3ac93200be27ad81df4327197c8d1a1427209a25n/a Quakbot
2023-05-18Hualr.jsjs 714d6297effa9020249e19940853d50dcb2ba31d5301a716f34ddf73f9a58bf1Virustotal results 28.81% Quakbot
2023-05-18Isaes.jsjs 2c402bf5ac40a8110c89bcf0f4ccd617ba22f8e8a6ca32d9949461c82540e48aVirustotal results 28.81% Quakbot
2023-05-18Wuvtjkc.jsjs e6823880248255f28dad73af6553cfbae133b6df9f78eff124a379d793265ac2Virustotal results 27.12% Quakbot
2023-05-18Cnipm.jsjs a3b99e8c39ad9b207f02de2422a94864986aae304adc635dc0cda1b27ac9e322n/a 
2023-05-18Dgbdiqj.jsjs 7723afb8d2a1417a6f0c808e628394b609e66227688064323ce47b25cb0505bcn/a Quakbot
2023-05-17Ltrulb.jsjs 683503e1ee6accf36b4e270156fa48982aeb9619157f07c35c1dbbfeb8a43e7dVirustotal results 29.31% Quakbot
2023-05-17Ciinfjn.jsjs a4fb26b40f74df15f85f6ee98f0faab524e9434e8469ea400fb9e1d4a53e6505Virustotal results 28.81% Quakbot
2023-05-17Geubbicb.jsjs 5526b208f51ee2b6adbf6b588401d5c1e058973988c16897fef27cdf25f2a51an/a Quakbot
2023-05-17Xmejxlm.jsjs 6e98b0ad9b6fe81e7dde4a5e76cddfdc25b19695ca702e4faf95f45dfc5a65e4n/a 
2023-05-17Ygpihdm.jsjs 8f330d0bd33cae1207a38406d6db47ef79a72bd8d18681a4a0f3a3a33ec3e4f3n/a 
2023-05-17Smwvfng.jsjs 15abbc922de384ed273fbc1a2e831ab1024bff793998f2cea3c69abd68a85566n/a 
2023-05-17Wxhhicg.jsjs 32b63b6f4ee01c7737a32e2bfd61aca2c688fdbd79e9455010a3a5506954ff0an/a 
2023-05-17Zwrzb.jsjs 584680760762a6814ff84e38f5de401a9ba356c834f6302e03634c8883180fd4n/a 
2023-05-17Tzfcev.jsjs 7c6d5f0448dd926c8dc6ed8d613b9f04ac81bf70df77505cef83271f342f334bn/a Quakbot
2023-05-17Zjgwhnrs.jsjs eeeb4508516ced092ad023afb6d760be8e24e31ecfc0a7344587cfdffadaa797n/a 
2023-05-17Hrwndg.jsjs 2b86f35dcfaeb1419746155c3c6eb49f499babb46086da61a4d920db30ea20a3n/a Quakbot
2023-05-17Pkenm.jsjs dfb5035d0e00d7b956c3a05cf1775df0b71dd9282afc5caf4207a6256e62d148n/a Quakbot
2023-05-17Sdkp.jsjs 276e82906cfcee307109c2f2fd23aff1bbff313ce10a01f111d80e8cd8465f68n/a Quakbot
2023-05-17Knprsma.jsjs 2a33d4c6645240387982b3c92ba6ec3e81749d635d14306d48bda923dcf0f723n/a Quakbot
2023-05-16Nbxgm.jsjs 4d16d0c2c84dac5c4c0edb4c27d8a26357f537749e69f06ae334ca86d33f3498n/a Quakbot
2023-05-16Prmh.jsjs 10d89d0820b229414fff3883079adc40e7aee3546b3691d7e6378a8f22899ea6n/a Quakbot