URLhaus Database

You are currently viewing the URLhaus database entry for https://shagodambeacademy.com/xet/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635073
URL: https://shagodambeacademy.com/xet/?1
URL Status:Offline
Host: shagodambeacademy.com
Date added:2023-05-16 22:00:10 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:44 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 3 minutes Poor (down since 2023-05-18 21:05:04 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Vkku.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Vkfqt.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Oqnqirnu.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 23.73% 
2023-05-18Vjzsil.jsjs f4915f167c3fb3624d4d085f3c8bed83ad6edb3d7f55c9b9bb17a4f06111e131n/a Quakbot
2023-05-18Yket.jsjs c56bdfe438e6261fa00e5e48e3e9896927886b959c2947db67582b4cf0f08e74Virustotal results 25.00% Quakbot
2023-05-18Tswaiuph.jsjs 6f741f3bd19d3433e0618cd31b85f73aa09fb1dfe670c9e5a8e0ec01cf274495n/a Quakbot
2023-05-18Abcwo.jsjs 9d55c860ce682edea5933b6e9e441703b00b9880087fafd62ecedabf0665836dVirustotal results 32.20% Quakbot
2023-05-18Eehxhn.jsjs 4a91fb2765da3056fe04bf5254fac9eb72f1fb4f8026845d71ffe672d4daac8cn/a Quakbot
2023-05-18Gmqvs.jsjs 506d6f7370fc1f1367a79bb76a39e5ed1e2c5113ca286350f3239788538fa80bVirustotal results 25.42% Quakbot
2023-05-18Xicjvq.jsjs 397ed6d5f113de3b5a638878e1ab22bb58f5fb493aaef92441db571bcb4c81b5n/a 
2023-05-18Pyqki.jsjs f95ae26c9bf7ecb6970afb88bfa12c71eafd8b35160d2c1658e57d36ea915477Virustotal results 29.31% Quakbot
2023-05-17Uavyt.jsjs be61952594d1dcb5774683bd939e4e278b596ba069248f2ff16fc39f2351936fVirustotal results 10.34% Quakbot
2023-05-17Zcsuyq.jsjs bc100a785f531874618920cd99c357dfc32c33cd59fc6b19856a94b41ca3f07fVirustotal results 30.19% 
2023-05-17Ummk.jsjs 170ceff8d051e5addeb6beb1128383fe814b7b40738b54c0f99409de5ccba2c6Virustotal results 25.42% 
2023-05-17Ulqmpoom.jsjs 8ee5d86b74cd803753d211be4c64578d8d39e7dd487d114bdbe044505063bb7en/a Quakbot
2023-05-17Qivghw.jsjs a70e07343087b1341505ab67207e4f4d1170a7ae25f9b7c90ca2eab5663e3db9n/a Quakbot
2023-05-17Qczh.jsjs 23fb378ba68beb5c6b1281c46215b56754ce9f89836c50f35b59615c2f79b455Virustotal results 25.42% Quakbot
2023-05-17Uixllqp.jsjs ff4f21489a82d5367cbd581c4dde86dc238f869b950e07bf20f3928f7e6c7567n/a Quakbot
2023-05-17Lzkc.jsjs 1f3d3d34fcd02bfbd9eba7becc4eb01342dffb209af4971f9df25374411cd1a7n/a Quakbot
2023-05-17Koopasr.jsjs b08ababb5026e44f20a22a8e5084ced4aae107ec1e7aef9e74d72282b1d61660n/a Quakbot
2023-05-17Odnfd.jsjs 2215eb3914ec784d8c0794bc3d7ee7a2407849deff6d41e8f9724a18a4dd4afcn/a Quakbot
2023-05-17Bltetmkx.jsjs c93194f7860e7edc7f5c3549f6d14f47048e5fa918ac64d7f096f692667e2333n/a Quakbot
2023-05-17Tgnx.jsjs 2a8cee84d6bb747aa85502533fedf568456f86a17bf20c648ba8031731f75b6cn/a Quakbot
2023-05-17Mouweb.jsjs 56d770912fbaca5d9ab9b227b0640b4439d16c32a354a018f5de6c2d9290919cn/a Quakbot
2023-05-17Ffpxsnc.jsjs 07f93fd06dc686125ab9023e639eaba7cdd6b3c585adf3477cf72ad1c4466de3n/a Quakbot
2023-05-17Zpxjobz.jsjs 99d8b15a8baebfb2bc6adb29920ee489b09f5b07db4200ed3a4e6dc10c593b2an/a Quakbot
2023-05-16Lolpi.jsjs 928a9ba429e54c8bb437af8c9cca4caf2fb431dd54c7b98565cfc3b84c5312efn/a Quakbot