URLhaus Database

You are currently viewing the URLhaus database entry for https://slotpaten88.com/mare/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635087
URL: https://slotpaten88.com/mare/?1
URL Status:Offline
Host: slotpaten88.com
Date added:2023-05-16 22:00:13 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:54 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 0 hours, 41 minutes Poor (down since 2023-05-18 22:43:51 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ktqi.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Lnmpk.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Qerikuzm.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Bnqqx.jsjs 204aba683e17baa35d35ffb9004b7a4a9c74ce8915b087635fc20d2c0d4a545an/a 
2023-05-18Emweb.jsjs a7559adb58fb8ca343a880d3a323c7307621cf7e95fee410922b0ee0d24d8bc7Virustotal results 31.03% Quakbot
2023-05-18Axmjox.jsjs 345e76a5091b5ecf319a57a8901fc203f48dae4dcc62b70fdc4d1e542d1a1f46Virustotal results 30.51% Quakbot
2023-05-18Ynyne.jsjs 426babf013bd614f1197dea8df2fac24ddfb79398b8310b46631885ec666eb54n/a Quakbot
2023-05-18Bnnlyofv.jsjs 6bf7410f1b32c7fad44030961607fb13ec400a2a008f5817485ba84c5c297175Virustotal results 27.12% Quakbot
2023-05-18Mxbybf.jsjs 5c2f413b69f9b93e5bf828d8c4219af88afdfc9d6fc5d04d749815dc66cd664bVirustotal results 33.90% Quakbot
2023-05-18Hamzihew.jsjs a9d658acf1c13639bef4615e65fcd8eaebd3b1d0c14ee826b7268e893878e5a5n/a Quakbot
2023-05-18Taujg.jsjs d6cb8ae70d4f102ac987c9de47abc6d962e10fa9755d74ea54a68edb6173dad1n/a Quakbot
2023-05-18Ljnfvj.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-17Gwibxt.jsjs 1a3fc3e2d336f6c024b0a452cf6eab7b5521bd6591f7ff15ac80caf4af268c3aVirustotal results 32.20% Quakbot
2023-05-17Gerir.jsjs 9da26f54018ef7b69e7ca172d1ef9d1de643acee030e0b25c66a5f27867c8833Virustotal results 26.67% Quakbot
2023-05-17Lowhtr.jsjs 2a38d5dd759f5e13e433429b8fbed42e9b1fa7de9f671bf87d0739862847c16aVirustotal results 26.67%Quakbot
2023-05-17Srbynxq.jsjs f7bc14c8c137444d5d046f1c1304ca9eb96509ce61adeffaa967dc07f21c17d7n/a Quakbot
2023-05-17Wjuzwige.jsjs 33f33ebc5ae78bdbf3a9afc064c64f1121c0214e1305d5567232cbc8779ab8c3n/a Quakbot
2023-05-17Muefpg.jsjs b207edc0255d1a287ff3c8f2e769e9540966bfb78068188cac44e1c350f704a4n/a 
2023-05-17Vpazbv.jsjs 83203bb6db44b0b8be7aebfcc192d2fd3ce2f8df163d64ba0cbbdcda58017899n/a Quakbot
2023-05-17Jdru.jsjs 5928b153ddf143dd91316c21023b6af8b66e687cb6a975c26b7d041ab7915069n/a 
2023-05-17Wvythzx.jsjs c335d6d854129d7d40d10e1bde31053f36f503ec7930374faa25ab5f93bd6f11n/a Quakbot
2023-05-17Mfizsrxs.jsjs 08b32ba293c2f156a805f56bac240e53f084079357c102f0621156c2f1f317a7n/a Quakbot
2023-05-17Lhcvsw.jsjs 1a1354483010667c195fb43a0bb917bc66e48227899ac6ead572e0829e34c1abn/a Quakbot
2023-05-17Wbgp.jsjs 9f53d9ae380240c124d0436279a19d75d28f9e8717207fddfbc6ea72072b7183n/a 
2023-05-17Bwhirg.jsjs 94897a38b2803cd1ae58242dbb02a3d963bb150a6c65af724acc0f75645c6459n/a Quakbot
2023-05-17Fbkz.jsjs adf92a3f715d23841a6baa800c4fcf45cebbc037b5754fe2b0b45e1fe78a5cdfn/a Quakbot
2023-05-16Nsqrjhe.jsjs b8d582c72c8fe6d0f7ec800aafb460b1b817427129d92f45ba171a8142f9fcb9n/a