URLhaus Database

You are currently viewing the URLhaus database entry for https://shoponhut.com/etaq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635080
URL: https://shoponhut.com/etaq/?1
URL Status:Offline
Host: shoponhut.com
Date added:2023-05-16 22:00:11 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:47 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 32 minutes Poor (down since 2023-05-18 22:34:44 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Wkciq.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Opzeadrl.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Mykh.jsjs feeab1be03008c309abd238cfcf4a099ee01537c3231d9e23f3de06b51db482cn/a 
2023-05-18Tgie.jsjs 7a515185d1c204dc897de0e485dd2dd335341156b5b7764220fb6df27fdbeb16Virustotal results 25.42% Quakbot
2023-05-18Bese.jsjs 992ec3c1bccb3793a6ae36e909056122ef9e442c16c17bcf9d771c90b85ee980Virustotal results 22.00% Quakbot
2023-05-18Mdsgvh.jsjs 56e7ef28abd5d99579c0cda0cafc94f64335c3b99a2c4a88b27c75bc943583d6n/a 
2023-05-18Wnca.jsjs b9c9809b0db8c089d16e6f9223ed8a4e5c74ac2b18b9f60ffdfb52ab0e82ab9aVirustotal results 32.69% 
2023-05-18Pwia.jsjs 456c54257858cdc9347b6b71444659a256ae3a000dc1c82298d0fc65ba890687n/a Quakbot
2023-05-18Jtjbpdhr.jsjs 0e8413c3fd2b87cd2139ba54c718d6b9f305a8bf33d41f05aaaa2639ccde842cn/a Quakbot
2023-05-18Fgcsyec.jsjs 83a6906128b93fb8777e46c5a7c736321ce2cabe58ece643b53dd9884a1c6c77n/a Quakbot
2023-05-18Xfiyoq.jsjs 17dcb0baeee21444da6b254c7dcd1d98989c6a0c089b8d79530a2c2a83dc34d3n/a 
2023-05-17Jfgwxo.jsjs 1e96a7079b653386193018082948ee18ee1ca517dd96395eb46b4d5e30507b87Virustotal results 30.51% Quakbot
2023-05-17Ieux.jsjs 266bfb248bbfb5fafc879d0a26c731499ccb3de4c57b64ce4b3a3fc6f836b93bn/a Quakbot
2023-05-17Bqazxk.jsjs 170ceff8d051e5addeb6beb1128383fe814b7b40738b54c0f99409de5ccba2c6Virustotal results 25.42% 
2023-05-17Ugcew.jsjs 02caaf8685c239c1d2e1a5e8440a7c9b39c4b12921ba12cfce6caf0214ea2df6Virustotal results 15.25% Quakbot
2023-05-17Jivldyx.jsjs 7723afb8d2a1417a6f0c808e628394b609e66227688064323ce47b25cb0505bcn/a Quakbot
2023-05-17Bldpsbm.jsjs ce9600cb7b98a80d9b5d95e0c7313cc05680b28366735b96104aa3fdf9ac0115Virustotal results 10.17% 
2023-05-17Levcch.jsjs 78416fcca7554fb3cc440610418511210e0dc5abcebf75ace7c1ef65d4d29216n/a Quakbot
2023-05-17Wtygw.jsjs 2ca32acefc61997a0af8f04a797f5f909899ba05c86e69d5cc452c5000b335f5n/a Quakbot
2023-05-17Lkizxepu.jsjs d23b1f39d4330a9862f4ca0b3f49032591a484094180aa425a221f224dd01c1fn/a Quakbot
2023-05-17Cclak.jsjs 434f7acad7e0362af702850da832cf1665957a3b131fd56c5e1d5ba2b6716dc0n/a Quakbot
2023-05-17Ivpctx.jsjs f392625f360532e5f58b8e94e33fd80eb3f7c1944be58a37d5c95929bfd00ec9n/a Quakbot
2023-05-17Lukmvfkk.jsjs 84f2b6262d864344b40f88bb504ac34135f6ed52dff39786f8cdec93f46cad34n/a Quakbot
2023-05-17Ndah.jsjs eb4538025a5e999aba814f807868e0f35ee4cebb209f975021a52b02e0d3b269n/a Quakbot
2023-05-16Jqoca.jsjs b810cc3b65242a6eab72093856b806dddda8237e6842fae00b9597a2c1565753n/a Quakbot
2023-05-16Rrge.jsjs 25dc6ee9f34d40c9960a6160d3d684199f059a4c984112d777f0647a1aaf422bn/a