URLhaus Database

You are currently viewing the URLhaus database entry for https://simraagro.com/aas/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635081
URL: https://simraagro.com/aas/?1
URL Status:Offline
Host: simraagro.com
Date added:2023-05-16 22:00:11 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:48 UTC to abuse{at}GorillaServers[dot]com)
Takedown time:1 day, 23 hours, 16 minutes Poor (down since 2023-05-18 21:17:51 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lxtw.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Wqwq.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Bzsj.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Zuxacn.jsjs 4ce120da3377eb71837bbf2aa992f1527837ec59a84af191f5bca1915fba6b45n/a 
2023-05-18Edyz.jsjs c8a758378f159844a29a298ad405833f7e8042fd38c5f75d36acde27dd485dcfn/a 
2023-05-18Birptnmg.jsjs 0836ece78eb77f4b5ebf101fc5e4317ad5554305bff6466db565f247b93b5928n/a Quakbot
2023-05-18Atkgv.jsjs 7faf3851af4522294594f1f661ae893ca01e462da47aeb7214a3b78b523ac9b1n/a Quakbot
2023-05-18Subv.jsjs 86fa62e0346304f7f35a32db756544d5f0b031a7794b54ab9008570bd7ef65f8Virustotal results 20.69% Quakbot
2023-05-18Smrdvd.jsjs b267e2261f79527d447d6a639751fcabcf68f9640e62a3c3106b4f750cb07b66Virustotal results 32.76% Quakbot
2023-05-18Fwrdbsp.jsjs ef1c6b9ad4a7758ef25a4557fa7bf0a20ab6dd57c36474a91ef75620edd0974dVirustotal results 25.42% Quakbot
2023-05-18Nyuoaijv.jsjs d8227132d7300d02c5cf46a7c7c4ea76a6fcd10c516382dad0a8892266612025n/a Quakbot
2023-05-18Hmsesbv.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-18Veadup.jsjs fc4e17680da39bbf2dfbf388da243c919927a825eca7d8de8a39d74be04968e9Virustotal results 31.03% Quakbot
2023-05-17Trqn.jsjs 7b501e67649c8608b6333e95e174a2d3db77d745651cf4142c43e79b0e1ed927n/a 
2023-05-17Atlqyxn.jsjs 148425d44762a381cbc5cf7c9e0e7fb44d71f7162439e78b219929274f34d19fVirustotal results 25.86% Quakbot
2023-05-17Dkvluymv.jsjs 77a97bbae92dc7a7845ded72bd28a849a3c41c2912628816d93ff4b9a27ed45fVirustotal results 32.20% Quakbot
2023-05-17Ubyyir.jsjs ba77ea0ae3afe4582d390d1930a3792bde2ba411df7e3c05ae156306c5cd46e4n/a Quakbot
2023-05-17Usjih.jsjs bb118ed7175733d7b31163818a3948e5e35d0e3ab3627a549e93cf6afa196585Virustotal results 29.31% 
2023-05-17Rhhtg.jsjs 0ae16f66866567a01f4af47c0c7b2e49d1e54eba4e457b2de97f88c48016cedcVirustotal results 30.51% Quakbot
2023-05-17Ioidv.jsjs 6cc345a8ad3df8d8da07821f31095f9c217201e0065038c5bb7e15aae14a9035n/a 
2023-05-17Skod.jsjs 56a3aa31a0b9a61a7b8a86c360d20d6c482af4c59c16d2d29d2bce329fc1e19fn/a Quakbot
2023-05-17Glfea.jsjs 5ffb6de1825b05f11c840a8e1c2713b9cce6fa54d95cf1f8f4416674fe06da97n/a Quakbot
2023-05-17Vjhl.jsjs b26bafd9d60c1f662b3e0b158f5c34af299fa81f5dd25dda6e1ab8b31e7058a4n/a Quakbot
2023-05-17Rtirfkcw.jsjs e5a64b72b7882e6328e9d9470a33991253981bc1ce941998f418f30add0e3f89n/a Quakbot
2023-05-17Ytmggh.jsjs 9792322c636ea83023b4253c29ba4528f4f6c0fa7edc3f59ae5dcdd0b0600df6n/a 
2023-05-17Ljey.jsjs 873872456a194f48214b11c1961ca4774eac337d405c9377e9f609d52edf5925n/a Quakbot
2023-05-16Crdom.jsjs 3040a2bceaeb5e3ee796e5c795814419de14bf1bea82fc584af85de775c442b0n/a 
2023-05-16Mbqavkjd.jsjs f68193f0ab935f1fa8db88a5f721de78d5476edb6e8626eb4d118425cad15ae5n/a