URLhaus Database

You are currently viewing the URLhaus database entry for https://sendasa.org/uetu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635077
URL: https://sendasa.org/uetu/?1
URL Status:Offline
Host: sendasa.org
Date added:2023-05-16 22:00:11 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:44 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 24 minutes Poor (down since 2023-05-18 21:26:10 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Mhcta.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Xyiy.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Vxsctcw.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Syzsmom.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021an/a 
2023-05-18Gqqbdzkl.jsjs a2f17ffca655028bf5663349090771ded5e0eac6f65e71d0fc151816a2dc7342Virustotal results 23.73% 
2023-05-18Yqueht.jsjs c7350bae160037853cf976ce2975bb3bf2a766449f69080fe67c733cbe18e005n/a Quakbot
2023-05-18Owrzk.jsjs cb46274d330ebea266c559fd5e391bd171816f40b8a0d960dbacf22c23a94ea3Virustotal results 30.51% Quakbot
2023-05-18Ngsbxdq.jsjs 783e0a457afb1237e0956e6ff847bfcdb49ee23036f51b4621b534f54d67112cn/a Quakbot
2023-05-18Elnbt.jsjs 35d190768891092e8f8616f00d3025020bc0f09ebb09adf865eae0b23547a459Virustotal results 30.51% Quakbot
2023-05-18Ajgmfqu.jsjs f7e8b96be3ac805e339ea8216ff018b90165280b8feba0fb873973b6f18ca747Virustotal results 27.45% Quakbot
2023-05-18Yqwqwyrd.jsjs 43f0a123b00abe19f1412b6fff2944e5bf4436a2ba20e3493ba9708ee5088c8bVirustotal results 24.14% Quakbot
2023-05-18Csmoe.jsjs 356f8c2ebf3f6ab97ed37e1195e6ccc8d5441e37c038c0c09c7f481b5aa205den/a Quakbot
2023-05-18Vrvaa.jsjs 16caea9932a7ec64a3898dc621d943071edcafd1ebf99fcda24e82ab6aa52733n/a 
2023-05-17Hvttozh.jsjs 320db1d64ed5a7a4ed401ebf9861a9776e220be46c59f4113bebf562f9e506f3n/a 
2023-05-17Eezdf.jsjs 093f4994d50fb15a657ced4731d4109a45ae410dbe91554d201d3ad2c44501acn/a 
2023-05-17Drfcgkis.jsjs 2805dc9f718f68c7daf0cae2b00b6ed8bd0a6e3a957fcf340055a17cc4ef7ef9n/a GuLoader
2023-05-17Smeuhlu.jsjs d5310c601c98c90eb1149ea53a24b05711bab888bf14ec14f88d5c7bb5dd59ban/a 
2023-05-17Kpqt.jsjs 6d5e3d77360658771bba4d35e8dd94a77d30f33a7c30ab86b66e271b54d2a638n/a Quakbot
2023-05-17Xqkrw.jsjs db756aef0c52e6f31a7cb628eefe67b0cc7d656427dd2d71c87ecce62165b562n/a Quakbot
2023-05-17Dtcqz.jsjs e29a41a9d60625c8b7ab2e66896cd279af26a9abe095095e8f71d39a518717dbn/a 
2023-05-17Xzvuleq.jsjs 4e7f6a5727864926c470c3134b666199c57b6063071bdf780ba0d4e313a20e5cn/a Quakbot
2023-05-17Kymzil.jsjs 6b39762d24daad97aab535d570991008513439de0406e9a85e5dcc10a1dbeb78n/a Quakbot
2023-05-17Xfnsab.jsjs 4a59519408d51432e7097e0f2bf0c22fee9f46f7cd31fd5244e5953942f32c74n/a 
2023-05-17Zkwmzosl.jsjs fed3147081ea494b122d5499778c5f82390409b169a655ca7f5db422b719a37bn/a 
2023-05-17Nymymfr.jsjs 580828daa318c726ac5f666d7a2675f2003790e66927cf6d84b875d2829d32acn/a Quakbot
2023-05-17Deifck.jsjs 95d25981704027ec116af56290889eac1877df6cb945b2ee5b368777f6cd2dc2n/a Quakbot
2023-05-17Zbent.jsjs 01067e05b4ce091903f0c7e0d0f2984975cc193f44099877104c64ddfd388db0n/a Quakbot
2023-05-16Zgynz.jsjs da8eda1f4cdf8023b96e41d411d73f603044fde2f962aa18f68eb8f796ea16ecn/a Quakbot