URLhaus Database

You are currently viewing the URLhaus database entry for https://pakforexacademy.com/eni/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635066
URL: https://pakforexacademy.com/eni/?1
URL Status:Offline
Host: pakforexacademy.com
Date added:2023-05-16 21:59:19 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:38 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 23 hours, 33 minutes Poor (down since 2023-05-18 21:35:30 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Jpky.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Sbpi.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Lrad.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Jyocdl.jsjs a173417d3a22a20bdea7ab969c0d1a69443d766e1e5e0cf68361c932def27a98n/a 
2023-05-18Usxmfzni.jsjs 93492712919e0adee85ebe16363f99eb8fdbfe7f055f8645bf21322ce803cc13n/a Quakbot
2023-05-18Jhuic.jsjs 79126f299d6fa3d58aff457d118ab11356537345d798c52cf1849567bbd9156dVirustotal results 19.23% Quakbot
2023-05-18Cfcukgm.jsjs 9665c60390e6de64d398dc14f91957bbec2a396ca2c0ee79cde6f8ae0e2a585dn/a Quakbot
2023-05-18Cdxfrdif.jsjs aa49eea2c5b828df4f85742d3d76bc365ee6c18721795dfe567bd8be0b360d61Virustotal results 28.81% Quakbot
2023-05-18Ljudw.jsjs e84b4920d25503f9505dfe8813b964551aa485cc176eb30dc5ac5e46dd5d56bbn/a Quakbot
2023-05-18Ovoj.jsjs 9d4e35c32d73270df3c5bf64cd693e2933e614075af8f15eeacb3fcd142f8ceeVirustotal results 28.81% Quakbot
2023-05-18Yaxujxa.jsjs 9fb9192d902b2bec0253263ac7de12696284a3203d04c735faf491c94c94ed32n/a Quakbot
2023-05-18Uadjm.jsjs 4de3c0071371884b0a2e8815554e19a2c0d89112e1bd9bc512d30aa306d3f0a9n/a Quakbot
2023-05-18Teqwwh.jsjs 287c569bf794a7ec47dcd5f308d39f138b6b4b964ad50c335991038cafd9d476Virustotal results 32.20% Quakbot
2023-05-17Qydimvf.jsjs c11631875df89e8d792439c8e9f573ebf097e4bc4926ace66626297639e4bf74n/a 
2023-05-17Daiukl.jsjs 0d025c1350cd713034b5b581118f5b7a71d0ba2551cc2321adbd286c8493fa25n/a Quakbot
2023-05-17Ykrirnh.jsjs 928de378e1b8690de67deab709ed80da406ac542daf31e7c5859f02c0b9a4240n/a Quakbot
2023-05-17Stoj.jsjs 92f5060e9693041974047a3d61fa5f29676b1451f9f09d9dcef17ecdde52367dVirustotal results 28.81% Quakbot
2023-05-17Jlfbrfcg.jsjs ad227c276250c72ebaf4c13e5d960347009d0762b8c2e696a35b36232e0eeff0Virustotal results 27.12% Quakbot
2023-05-17Svwxpaof.jsjs 404e30334a58830297758dd73f2fee67f6ed0ea8c6d7fa501d7eb809925d82fcn/a Quakbot
2023-05-17Laqg.jsjs fd6447c1e9b59d7114534e32bd988bd00fb674bcecc4c3d958b096bfc06b4acan/a Quakbot
2023-05-17Lnrpsdwa.jsjs 86c59dd10ace0e82634fdbc454cf01a48bf4355a6576c1560325847681ce10ben/a Quakbot
2023-05-17Zmbamke.jsjs 36e5d3bf6af42e413df66a4b48e1203aa08a36a3df4a76aa9aa1dbb9d70d64d3n/a Quakbot
2023-05-17Yfxpju.jsjs 678146c4c4a4b718035adace7ba4bc7d870e9f27f249b51b8a8ffa394f64cb98n/a Quakbot
2023-05-17Xgumca.jsjs 8fb72e300be0c8eab885f94130289e14cf3d7398ad8d945a28fe41a1b9e58304n/a Quakbot
2023-05-17Vnub.jsjs 4f41a5b8302828cf18bb5a6a92c70633b31150adaa2dabc2dd89cdfa754cbcf9n/a 
2023-05-17Costtfux.jsjs eb2a74df0d6c5ce64dab17091c61f93f88ea77c1b5bf7e7b8366a3bcc3f6ad44n/a Quakbot
2023-05-17Ucwo.jsjs 8f2be880209ff3409501462487f3f93bdfb93e4a80c9e41c3929236094c0d6bdn/a Quakbot
2023-05-16Mtnjvij.jsjs b6e1a9b4eb14fde105de917db395a0317af3cea2c283bbbdd8f2a3b06487cba3n/a Quakbot