URLhaus Database

You are currently viewing the URLhaus database entry for https://singrour.com/aser/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635099
URL: https://singrour.com/aser/?1
URL Status:Offline
Host: singrour.com
Date added:2023-05-16 22:00:14 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116918 created on 2023-05-16 22:01:07 UTC)
Takedown time:2 days, 0 hours, 37 minutes Poor (down since 2023-05-18 22:38:57 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Vaui.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Ltvxfari.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Macabu.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Xlck.jsjs 4d5930fafddc2692e6c1a340c6245c1808561d2295d342f2cbeea65191d05c43n/a 
2023-05-18Hpwwbxir.jsjs 8f330d0bd33cae1207a38406d6db47ef79a72bd8d18681a4a0f3a3a33ec3e4f3n/a 
2023-05-18Fohbmxp.jsjs 8116e7914df0a4fae9adad12da668660206754557fac016131c53fcd305d537fVirustotal results 33.90% Quakbot
2023-05-18Hfdewagb.jsjs ac2f114a6bac8df9444849169360217c9656b866153cfc42dc444cbc6b7b6e35Virustotal results 15.25% Quakbot
2023-05-18Mgawr.jsjs 7217ae2adc382459d109d0ca1135074318d85578de92f3c231dd520402b6d647Virustotal results 27.12% Quakbot
2023-05-18Jthrphy.jsjs 0ae16f66866567a01f4af47c0c7b2e49d1e54eba4e457b2de97f88c48016cedcVirustotal results 30.51% Quakbot
2023-05-18Lpnzbq.jsjs fc35a5a51f420de2456b7dcb8c59dfcfc4a5a995abb8201286aa81cd0c391508n/a Quakbot
2023-05-18Zkauir.jsjs 1ef243d363359aa7c5d8ab0a55ffa52a9302f63a3750df5b8408c99641bb9ab9Virustotal results 25.86% Quakbot
2023-05-18Lqqpdsz.jsjs 41004cb0d270673cab3af5cab1a87b9c6c88fd3a43f9a28494997c13652781c0Virustotal results 35.59% Quakbot
2023-05-17Wolsd.jsjs 9fc93269f064d50db15333e3dbcf15dccb35094dc51bedfc465ba99ce6a37953n/a Quakbot
2023-05-17Vbiphxiw.jsjs 05dab37be019900d575f8a51485f2baecb4fe212712970c486fb711a173c6290n/a Quakbot
2023-05-17Qwey.jsjs 6a23cf1558f0a3efb0abb0f298f9716be0446165e859f1116485a847cf57442eVirustotal results 32.20% Quakbot
2023-05-17Bfsimtxc.jsjs ef903a00f557175fbe1af9263796fbdaad81dc6578e948729821675219196f43n/a Quakbot
2023-05-17Fhcmlduu.jsjs 77c78781fbf40291d31c545dd06a094505a49bd415cbeed6b922cafc6af07586n/a Quakbot
2023-05-17Wqwjz.jsjs b95a6f4518de9f894317d0fe03a9dbf1132ea5b5053e9f11d63ac0746afde62bn/a Quakbot
2023-05-17Gtdu.jsjs 93be05e8c37282bca34649a25ba07962fb7da33e5799c01e05c15cc3b72589ecn/a Quakbot
2023-05-17Vbtdfjs.jsjs 42d74e9be0d442e0bbebc6134157922913abc72510b235bfa67b53092757a2f4n/a Quakbot
2023-05-17Mxzrd.jsjs 556206a8c2d04e13c39085e620f6f6071d61bc55eaa6018434ea2383a723a5c4n/a Quakbot
2023-05-17Fnsnxni.jsjs a6615e2409a33f699f2e4d4d063b37a765604a6545fecf85aa540fad5692f636n/a Quakbot
2023-05-17Bhwhgr.jsjs 38c5cc1cbfa5180c120884bbcedfe32e9159f2cb35970601f8779cfa2cc9a566n/a Quakbot
2023-05-17Cfim.jsjs e56d8c1cfcb387d1fd1fe4e116e0dd70ecd6fa610ab13fb6ed5161856c10dc74n/a Quakbot
2023-05-17Wvvevqi.jsjs 5231ecd7cf2629bd626ba02b1322793cf7f04739df582f0024e8cc713ee58752n/a Quakbot
2023-05-17Oirobt.jsjs 37d09ff52c0e8c464361188180baa3da2e53ec50f53e738644b88dd465783c6bn/a Quakbot
2023-05-16Gxhsra.jsjs 22ec9731abc6b104818ac3987533021421ec2bcb040f1a4705f15fb348ac4cefn/a Quakbot