URLhaus Database

You are currently viewing the URLhaus database entry for https://simu22.com/svpl/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635106
URL: https://simu22.com/svpl/?1
URL Status:Offline
Host: simu22.com
Date added:2023-05-16 22:00:18 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:02:05 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 34 minutes Poor (down since 2023-05-18 21:36:26 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Umucna.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Wehwl.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Wctu.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Wqftr.jsjs f175419410a0263d49f5bb0b0fa3b2a35f4a32b483dced7551ca4c8c3cd041c0n/a 
2023-05-18Ecao.jsjs 2c91bde6a534aee746616dd47460479f4813dd91fa6b608246e4cbd908aedf83n/a Quakbot
2023-05-18Pxrjyztv.jsjs 4ade6f7d7cfcd03dbffdfe401ed93fa601500252c858fa6010e54b0587fa0249Virustotal results 27.12% Quakbot
2023-05-18Efubhac.jsjs 2ffe30857db286ab5839fb47499480fff446371b3c1f8df2d8dde6853266f088n/a Quakbot
2023-05-18Bdeg.jsjs 92bcab1aebfd8fc6b8ed37048bab5574189469b98f8152e71b4c41106be5e52en/a Quakbot
2023-05-18Sxryz.jsjs 0c1a4acb8216ade3632625958fc7427a5f996f5570d05d649a0e49be5e748ee9Virustotal results 27.12% Quakbot
2023-05-18Jsdc.jsjs b9c9809b0db8c089d16e6f9223ed8a4e5c74ac2b18b9f60ffdfb52ab0e82ab9aVirustotal results 32.69% 
2023-05-18Amcdr.jsjs e8a4b575211295a78e536c4a374d5538f24470f6036d3a1e5ab52f149b6a5683n/a Quakbot
2023-05-18Eraky.jsjs 17ee5a686914f6713574da4e30d7902af9bdfc03eb0173e1143cc97a4fa37b75Virustotal results 22.81% Quakbot
2023-05-17Rdkirvl.jsjs fceef22558799ba34afb830f44f63ff2d0386112e3506a24549d220e7ab2f4d1Virustotal results 15.52% Quakbot
2023-05-17Crjd.jsjs ccfd3d544f060b0b45133acf8df8a753724ec29a916820e53f6e7692dd785c8dVirustotal results 21.67% Quakbot
2023-05-17Rbrwfq.jsjs b22c3068eb2fde1d32dd3e2ce301ae348c6baefe0a01c2b50703b10083122ae6n/a Quakbot
2023-05-17Uarb.jsjs 08b43f87f3dd81d9be92cb99ab4547399f67348b7ffe33011b49947b98a44046n/a Quakbot
2023-05-17Rywu.jsjs be61952594d1dcb5774683bd939e4e278b596ba069248f2ff16fc39f2351936fVirustotal results 10.34% Quakbot
2023-05-17Xivwtt.jsjs 576d80e7bad2be3b3f4ddb0ccbe067bceabbc990bb96e11007cc74c2d6ad7bean/a Quakbot
2023-05-17Gtyok.jsjs fb639f61394301ec51c3c82b270fa10118b12150f177db33a72560d80ad79f25n/a 
2023-05-17Hkabn.jsjs ed3b42a466d5debc63224e8439d69996fd4f174cfcae800ac31dd8dcb69c921dn/a Quakbot
2023-05-17Tgrgwho.jsjs 17cae6fefd4ffacaeba9fe3b034507cacd2d1ea9c6e6de9b6b291f0b2bece2e0n/a Quakbot
2023-05-17Rmdo.jsjs a67af61f3c8f513058edf508f8cb6e9110a03684ad9a0aa5c42876b257dfcc8dn/a Quakbot
2023-05-17Dkqvd.jsjs 71aec6c4cae6c735b17cf60b9fe0f48f854ca7573a7a77d1f66694277fd511ecn/a 
2023-05-17Qcije.jsjs 86d4900d8ad5aeaf40a4fea969e245ade54410642795afbfe22feac6cef76035n/a Quakbot
2023-05-17Soyyncc.jsjs dbbbf25ccf2c1d14073dcdc3f60325e75d2c410f3106a4661fa76d45b233f44bn/a Quakbot
2023-05-17Hfgss.jsjs 85406a6650952dae61e659bb769c17341f5fcbacca4b7e602107a00583b547d1n/a Quakbot
2023-05-17Qvxoszd.jsjs b7167f46435933c5c70b273988dbbb2e00b64b480bcfd6defd02fa7c29ceccabn/a Quakbot
2023-05-16Grqkjzn.jsjs 5dbe4404035c7f64090f00408ba11ac18bb87d616c53d8127926f8070204c92an/a Quakbot