URLhaus Database

You are currently viewing the URLhaus database entry for https://spartanpapers.co.uk/ctas/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635093
URL: https://spartanpapers.co.uk/ctas/?1
URL Status:Offline
Host: spartanpapers.co.uk
Date added:2023-05-16 22:00:13 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:55 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 0 hours, 5 minutes Poor (down since 2023-05-18 22:07:46 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Yzskl.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Mjdao.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Yxznkzt.jsjs f4559402fc6f9e274e8800609aa65eeb9f63fc71eb453f595e9175f103a358e6n/a 
2023-05-18Xjgh.jsjs 106ea6e9df2db6267999fa9df4ae5950c1be2de07cbb773cd739bfaa29a806d4n/a Quakbot
2023-05-18Bsgcnarz.jsjs 655729ffaa1d79b40a1df6017495f362432d5497a1c79b18220fdcc46d21f2aen/a 
2023-05-18Rvikfyf.jsjs a5e07fd19c36096b65281a4da6788fdb724e4cc4be6fae21497a969c1255a622n/a Quakbot
2023-05-18Cobecp.jsjs b89d6433da85e8b53b60dd8f31aa096c923d9b4fb337c03d3b381482ef280974n/a Quakbot
2023-05-18Vmdwd.jsjs 4cfd3cea6e5aacf340993648b46bbd6628953021cc5148be665b68de39755e98Virustotal results 27.12% 
2023-05-18Jefcanjo.jsjs 4de2124d922958dc3b36346c1906578b79f12a6388ef771a7f8503c21e30af78n/a Quakbot
2023-05-18Kyohfe.jsjs 269dec903e55df2babe1cb8bb498ac7fe56d2a079cdf89c2d5c354b7a8fa1250n/a Quakbot
2023-05-18Xpadz.jsjs 2eaa6ab373b017bafebcf7e8d12609c6c9958b230ee8d4a3e4f96294f5ea826dVirustotal results 32.20% 
2023-05-18Wstq.jsjs c2b560cbbb7dc30cad06a2a6b715f07591269b172bde5101a639fbb04e4dd9cfVirustotal results 27.12% 
2023-05-17Krfujlrz.jsjs 26e8f5245d3928df93af31946f3ff6dcf2291861ef4835e6b23e145cfcf9f8d5n/a 
2023-05-17Xrtilaao.jsjs 2072042cbdf8458366261756217da566a1b8d6cf4b24541a37d71c44c07c7fdeVirustotal results 24.14% Quakbot
2023-05-17Gqiuqcab.jsjs 34af4640c3591095a1562606faa096b2cab669c17859f8b99df4321999b17373Virustotal results 22.41% Quakbot
2023-05-17Bqdrtu.jsjs da144ecfed0906bbac01d116a74626cd6fd7ec833680cd9ff8107dc94db16496Virustotal results 15.25% Quakbot
2023-05-17Eywexik.jsjs a84a8c5338c73e889cff9d58c510657f8624b8deedf847eef71befacab5ed60eVirustotal results 20.00% Quakbot
2023-05-17Udhjpz.jsjs cb296a47f490cbc70541030b87a0b2d9eb6c1253da849e9e37e7912f2fff796dVirustotal results 35.59% 
2023-05-17Shhdulct.jsjs 99ad6e2718d4fa53c8b3e7479802548afcde5a374d0563ab49ffb0405d8e435an/a Quakbot
2023-05-17Pajeqxzl.jsjs 75652638a13795119ddcce03233b582149abc3f31c91d1a618f635c8dce144b3n/a Quakbot
2023-05-17Wrpo.jsjs 42b8a361fb18aca63dc8da64e6831126773eb70e48d64a9743708027fabd871an/a Quakbot
2023-05-17Vemtgvz.jsjs 86acfff0e35c15db97d70f239c2df9bf037a65edeff97198d3be16466a3ed3ban/a Quakbot
2023-05-17Ptkhopwb.jsjs 11871f5e17b704f75a8fc37b7cd5750d19535cd3f26f8c2645ae8d19bf6aa069n/a Quakbot
2023-05-17Dadprd.jsjs 7b7c8b50f03fdccb39a85a1a192227cc40c78225a312e83f94c648a156c025b8n/a 
2023-05-17Hybysdm.jsjs 3fdec3af11b29f0b49ef287f581e8cafb90df6249eda2e4fd2432f9500eb22cdn/a Quakbot
2023-05-16Awbo.jsjs 5efad6218a72322820c919380dd6807ae34adfe6c5eabd3cf5f703ba4b5bd01cn/a 
2023-05-16Rkqdyu.jsjs aad96746357fbc7281fdce52052f11e02c8f9efba2bd6ddde2014c0f5c69dcb5n/a