URLhaus Database

You are currently viewing the URLhaus database entry for https://pattersonoil.co.uk/da/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635064
URL: https://pattersonoil.co.uk/da/?1
URL Status:Offline
Host: pattersonoil.co.uk
Date added:2023-05-16 21:59:15 UTC
Last online:2023-05-18 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:36 UTC to abuse{at}krystal[dot]uk,noc{at}krystal[dot]co[dot]uk)
Takedown time:1 day, 11 hours, 24 minutes Poor (down since 2023-05-18 09:26:35 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ssxvgzvq.jsjs 26e8f5245d3928df93af31946f3ff6dcf2291861ef4835e6b23e145cfcf9f8d5n/a 
2023-05-18Ahab.jsjs f517f6e7dd7c0f029a72fe25803ac2d5c54c7abcc8e576fbf95cbe6a87759540Virustotal results 28.81% Quakbot
2023-05-18Iygomg.jsjs c73f356c704556ac74d752c91963fe6a1c7273b77027b218016b83f03ca878eaVirustotal results 27.59% 
2023-05-18Ahoyffe.jsjs a957652292b9f2b69f858cd1f3221d9c4ae8b165a295b91459fd2bf2eedce715Virustotal results 25.86% Quakbot
2023-05-17Lttb.jsjs d7ee80c4c9f9a041e63b9e4a454dfa6c60dcb7fdd18ca658f2f92fc97f61d766Virustotal results 22.81% Quakbot
2023-05-17Eoaphzd.jsjs cb6a65f1e6220e908455c9dfaf1b69114b9b0c5666dc2b80f597d2c1e4ab29c7n/a Quakbot
2023-05-17Jjqpgrw.jsjs d1a92330c8f58a18b81d7ff1a9ea348b205fda7b106c31a2d1e09764a4557fa0n/a Quakbot
2023-05-17Unege.jsjs 8772156f90eaf1afea7ef8aede91a10a14f6ab0bbfc0cb8629917994af09f843n/a Quakbot
2023-05-17Xliwvjd.jsjs fd6447c1e9b59d7114534e32bd988bd00fb674bcecc4c3d958b096bfc06b4acaVirustotal results 29.31% Quakbot
2023-05-17Hweb.jsjs 24c2f222f6f2809f7c5dda15d789a41d9424dfce3714fe71bed9fbb0e077503en/a Quakbot
2023-05-17Oygrrd.jsjs 3c65c87cf0e371c576074e364d5d415f782faa5f2381909a0cd1d6d3e16b21a3n/a Quakbot
2023-05-17Buiwr.jsjs 07c7eed20a0deee08f2f4bcdaa5a1b077e9c5d50c6b1219c4082c3d54afc1349n/a Quakbot
2023-05-17Guepwlkz.jsjs 16d241e2e492fdd9808a32007587e8df3454f451b7903dfd836c95173691fd86n/a 
2023-05-17Cwec.jsjs 9107e1991b4799a977fec3c3670d2ec74826da71583af47be655b0f1406641fcn/a Quakbot
2023-05-17Avcelwa.jsjs 27fddaff07e3bd4b890979ddb288d629d1b9f7d19b269a176a2430e306ad19e3n/a 
2023-05-17Fqpkxma.jsjs a552ec015ca7ba1795f67308f1b094bf945316cef08dcd87ca3d0b69b6ef8324n/a Quakbot
2023-05-17Csfbeed.jsjs 75aac7528882d02b0fe2f0ce21f49abb0051a5b0909e27596368ff9dd0df0f08n/a Quakbot
2023-05-17Aybzaqwr.jsjs ef56a73f29510c8d111bde1204297782ee5ecb4f882949738f4aed01dfc8c2bfn/a Quakbot
2023-05-16Xqmigxsm.jsjs 8ff04e8f26622c415b912113adc1507906d644dace1758994e4c07d35b841553n/a Quakbot
2023-05-16Fmvwyjqu.jsjs 737e6ed2f747c0c50fd54ef994d260471883006d6d05b58248c363e7dfa4248fn/a Quakbot