URLhaus Database

You are currently viewing the URLhaus database entry for https://pipclass.com/nue/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635054
URL: https://pipclass.com/nue/?1
URL Status:Offline
Host: pipclass.com
Date added:2023-05-16 21:59:10 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:18 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 23 hours, 0 minutes Poor (down since 2023-05-18 21:01:35 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ldrvhn.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Wyorv.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Jmaxwgae.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Wqhs.jsjs 0b3324b249fb9e33cb3970056ed6166b271c1f678d65d34cdff6079bbd95f2c5n/a Quakbot
2023-05-18Kunio.jsjs 85341f4b78166b2b1fe18125caf6a187b8c29c45ce7ef3956530cfd4bd6591e0Virustotal results 8.62% Quakbot
2023-05-18Tiulgza.jsjs c2b44422f7f4e7dc1cd2abeab300413b55a00cd9d34fda7542a467dd852bafb4Virustotal results 27.59% Quakbot
2023-05-18Mvrj.jsjs 8496ebcccb2676a1fb21ed0fdf36c320fabcf9036d275af7acc025b0182e7963n/a Quakbot
2023-05-18Zaws.jsjs b4b9340a057e2f27555df973e95af7d75b991cadbf943c5f48de2cbda1e3edcdVirustotal results 29.31% Quakbot
2023-05-18Kuztnzc.jsjs 42b8297467af3118af88bc8bd71bc4b1cff09e2fdd17dd631cda319c5c4cf592Virustotal results 24.56% Quakbot
2023-05-18Udqvfuwi.jsjs 946d5e2c822a804863dd95b51f9cf5738b216cacbfd4e739d28af66952e4821cn/a Quakbot
2023-05-18Kvmw.jsjs 0c002b88627f5df1e7415950b066ddc51bf3e0f4f3ef5a2b01a266b2c4282ee1n/a 
2023-05-17Qimcotbo.jsjs e70a77365ffdf3f446781b46a826a0796adf73d479c783efd6763a7d83aec549n/a 
2023-05-17Gtelh.jsjs 819e1677a9b83e3e2c5f43d5b2dc0f2f54147bd8257c067505fb818330efc68an/a 
2023-05-17Csfxg.jsjs 0b5625e5e6c8ca17119f220fef0e5b08313f77e79294375e8b2c57d9bdc47ca9Virustotal results 25.00% 
2023-05-17Ushm.jsjs 2b2ddaf766a72a62c3247e520317d64f6b32231d8802b99b861cdbcd872a7ef0Virustotal results 25.86% Quakbot
2023-05-17Ynijppc.jsjs e34af5d0c51c9f5403ca9b2aad48f7f772322fade0dff21b839a90ac6420cd87Virustotal results 27.59% Quakbot
2023-05-17Rbzw.jsjs ccdc371fa95a2dc8192ecf73826f489942857addced0e8ce4b9aa969aa98381en/a Quakbot
2023-05-17Xbhnnqsi.jsjs c3e99de4200fa77aa025ca9c3691f352cd668d0a77b4f467305f66cb4f933618Virustotal results 16.95% Quakbot
2023-05-17Fjqivsjb.jsjs 582d7260d0c9d28291c1a5741818450399bdb826da9dfa44e69657727548f4f6n/a 
2023-05-17Tauepk.jsjs 85229e6d15f04400fc5209ceced151a65e62196ff7f1eb8b3919e6534df71bd2n/a Quakbot
2023-05-17Rynpsyev.jsjs 4ee2c21cf28731f050ef49168e1431b1cb0ba22e621e8792623f5f2965c4b832n/a Quakbot
2023-05-17Furmogs.jsjs d3aa6a63aa1f8353cade60d07a27e97f338089752b45b7dd9e152d2013bb6627n/a Quakbot
2023-05-17Znktpif.jsjs 54c1a521bcdf1d0a7730cf10bf79c170c601ec6f8874be40b683bfeb3aa646b5n/a Quakbot
2023-05-17Cuwqdmm.jsjs 9ce5055a1f9808dbf6a6ed2ff254090dd6d21a099fe67b6a41a6f5937a4ce98en/a Quakbot
2023-05-17Vmijotf.jsjs e5a16189da9aa775db1e166a95595f4727929f5addfb25b64a07c49d91c66e65n/a Quakbot
2023-05-16Vivoqjl.jsjs c04c1a19169e22d4b0edb74a9f7d51f3f81852c66076d7ff27ca5f9391916f3an/a Quakbot
2023-05-16Wijghqn.jsjs 7c2a2a0ec7f98475c259d1aa1c90773d1940674b28cbe14fe09abc13a458a7e5n/a Quakbot