URLhaus Database

You are currently viewing the URLhaus database entry for https://peruincatrips.com/etrc/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635045
URL: https://peruincatrips.com/etrc/?1
URL Status:Offline
Host: peruincatrips.com
Date added:2023-05-16 21:59:09 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:16 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 days, 0 hours, 56 minutes Poor (down since 2023-05-18 22:57:27 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uwsoq.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Qryulr.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Mkfj.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Xzmxtu.jsjs 67afb6fe01b12f4c199423ee3a1fea3df90003357fcf087a453754ac698f67ban/a 
2023-05-18Byviynex.jsjs 8110c40ddb65d964d81ab30f4c4f9bdce11b8956b986d647f4b81c4c0652f5a3Virustotal results 31.58% Quakbot
2023-05-18Rnftqbtr.jsjs 08a4ded15b1b100031a7d4d5816c32a45f5bf29a74bb677f99634db21d3cd646Virustotal results 11.86% 
2023-05-18Zfrut.jsjs 2878ea27fb0bf41510c5a442c350ea2d31a71ee4c1532dcabf74f79b9aa1b3f4Virustotal results 28.81% Quakbot
2023-05-18Fvyzyyjk.jsjs dff43d93176f7f0b50d2b960680eb78be307c219d3a2f9b42d969390818a467fn/a GuLoader
2023-05-18Eoujnk.jsjs 285384a5ccf94492475a9af926ddb24dc621f5b0f19df79f8ed7366ca130d544n/a Quakbot
2023-05-18Ngsb.jsjs 3657123d41437d5c2c4b48b03e14153b367398907ae10d30021c974941a5b64cVirustotal results 32.20% Quakbot
2023-05-18Hhkxieax.jsjs becfbdbbd5a9cfbb918940eafdd8f586133d77eb11bfc5dac1f96e7787abfd65Virustotal results 22.81% Quakbot
2023-05-18Mfooxfgo.jsjs ca99a531b2e34c4f23683a2cf2f4a2e81bcb2cc4975ba287d0bc6ef71563472cn/a Quakbot
2023-05-18Fcsggbnq.jsjs a4d5af2c7491cf9e8c6fc213f49572749af1f591ad0e453bfc3770dd17d884dfVirustotal results 17.24% Quakbot
2023-05-17Hasws.jsjs b9c9809b0db8c089d16e6f9223ed8a4e5c74ac2b18b9f60ffdfb52ab0e82ab9aVirustotal results 32.69% 
2023-05-17Zwfytc.jsjs 20336fdfef9d5684dd6055ff838104e334316b82122b0a12b809b529b1a66cefn/a Quakbot
2023-05-17Pmoz.jsjs 4422126c61949a9848ddc759de968eb699c5364973a271dc9aac631121591d13Virustotal results 27.12% Quakbot
2023-05-17Foggkfb.jsjs 5eecbea9208745932f291b3156e7036997e4b1e93f7bb53a270cae7c125aa079n/a Quakbot
2023-05-17Dyglbja.jsjs 11ef57c233cd2baa14c4cfb9579839d381fbdec85d01923f9679f5ed21935f52n/a Quakbot
2023-05-17Vuaqnkp.jsjs 959eaab7d50ed2022fc6403b969a196f340861c5aafaa73ebd170ad225699275n/a Quakbot
2023-05-17Frqtvm.jsjs 028b5be552309b7db0a086516c31eae6f10735c46fe79bab9d9297e2ffebcaa4n/a 
2023-05-17Ypjtv.jsjs fe5901e8858fe907919adc4b33e0701f1593aa7e037e419ba03fba2833439f35n/a 
2023-05-17Ukrua.jsjs 172ca8d470cbf01a08c2c9e1fbd450a000240c12f582f941a8624bf03c9f3642n/a 
2023-05-17Nknw.jsjs 8781233610f95606213224129eda304545aafd6ffb2a010d53d5240532bbfeb4n/a Quakbot
2023-05-17Pyvvvr.jsjs 896018e1013c47d1c2c72e53be7ac1cde2fabdf2743e7b3714d8529e92e762f0n/a Quakbot
2023-05-17Xihptyge.jsjs fe94bdf57b4a23ef64e2343a94958941caa213be6f7e7e896a7b1bbe456de64dn/a Quakbot
2023-05-17Envlmyaz.jsjs 9ada3047434b45135bd245df9a24bc3d8848399f71b496f581e239bb10743110n/a Quakbot
2023-05-17Sqxhi.jsjs 38d98a6ab8fd15a3d2e10514f3615dfd45faea46fe02f51d7629069502127006n/a Quakbot
2023-05-16Lxphylws.jsjs 0b48caa6ea1238e6d6eb8b57d73819b416d26ec8f39d5bf9abd5c848674fa4c4n/a