URLhaus Database

You are currently viewing the URLhaus database entry for https://techafresh.com/etuc/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635113
URL: https://techafresh.com/etuc/?1
URL Status:Offline
Host: techafresh.com
Date added:2023-05-16 22:01:05 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:02:10 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 34 minutes Poor (down since 2023-05-18 21:37:08 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Wjhm.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Hvsvhu.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Wamu.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Ntjmw.jsjs 9c8da21730bd6ca998a21290326c34cbe7d5153ef1da6b8f1b55ee78bd6bd6d1n/a 
2023-05-18Lagwdq.jsjs de40c651da56945e6aa4f1adecf9ca842f4b2c630f3e1ad45c2c02952d4578c7n/a Quakbot
2023-05-18Qbfop.jsjs 66a44d6ecc0bff8550c4f8fd93b40851e019bac6297339dd180d268ed9bba451n/a 
2023-05-18Uixsxix.jsjs 6730ba9eb12acff08b5c019bd8587f2cecef533f14a7ca9fc80e7ed001bb903cVirustotal results 30.51% Quakbot
2023-05-18Nfyps.jsjs 6d790992a3828c5f421e6c85ac319d61de4eb5320ff67d91b8e5d4577865de5cn/a 
2023-05-18Grwnkh.jsjs 3f5e5c65bd5814cdaf300e4fff7de23851e1c5fcc764d920ba42761515bc506aVirustotal results 25.42% Quakbot
2023-05-18Otgypfij.jsjs 85341f4b78166b2b1fe18125caf6a187b8c29c45ce7ef3956530cfd4bd6591e0Virustotal results 8.62% Quakbot
2023-05-18Zygs.jsjs 70cbe6d0639705257a62be9eb8da5151af27830bf379d05aaffea8a6d1f49b39n/a Quakbot
2023-05-18Cvju.jsjs cb2b2c5c8e0ff33bbc082310f5ad09305fb6f7b7e6d660efa2c02393341d6fd3n/a 
2023-05-17Iivipgsz.jsjs ad3a510115f62b2cdabc978db56cb5d93c372bcf45b52fa39d4d125e1cae3caen/a Quakbot
2023-05-17Xjdmalcc.jsjs c3e99de4200fa77aa025ca9c3691f352cd668d0a77b4f467305f66cb4f933618Virustotal results 16.95% Quakbot
2023-05-17Sqovna.jsjs 2643a0ad4d4922d9f4428188cfe85112015c48ec78826051b8fc118affc60fa4Virustotal results 30.51% 
2023-05-17Isoblbh.jsjs d8227132d7300d02c5cf46a7c7c4ea76a6fcd10c516382dad0a8892266612025n/a Quakbot
2023-05-17Sfbegoly.jsjs 5b2d175b18348c26ef8ad20f51fdeb4aa6ab4076aa57cc05caa3cc8772385077Virustotal results 23.73% 
2023-05-17Jerqb.jsjs 0eb9fa07ffbdae465ca7afa7b68b6b38311315046844cd6ac97c9e3b77d5fe99n/a Quakbot
2023-05-17Eeuv.jsjs 340674eac99b309a0a10a07f5d961e87788e88c4cc2f218da6cd61ccb196deecn/a Quakbot
2023-05-17Coxaztb.jsjs 784d0c23a7299fe8f5a79ce4f83765cd48535cf1afc25d542a0f854f8049d149n/a 
2023-05-17Afhytiap.jsjs 2b6a8712ec3382ec456b648eb89b98ecc372860d51b2015c1b2692fc652ccf20n/a Quakbot
2023-05-17Upog.jsjs 956bb14dad3d40043ecfdadef713be9be55f7dd3964ec5f9484af60c3d52070cn/a Quakbot
2023-05-17Sgwulo.jsjs ee451f0ca2dd65253c3084e4e31abb60c92942188638c1582547486040cb19b1n/a Quakbot
2023-05-17Dqin.jsjs ed7a6d431daf082eea610fb1989bcf74902608a005794952153f4f97d2c9ead1n/a Quakbot
2023-05-17Xhatxwgv.jsjs eae8cd9d33a2c2f5c03f9aff48cf52038841d2c645e892f9b052bf1102ba8d4dn/a Quakbot
2023-05-16Qhcsf.jsjs fbef83bbdedb45fe8762cedb178769bb4d015cae67e442b50418eb66750a79acn/a 
2023-05-16Opncgga.jsjs 13ac600f73064c617d77d51fed6df3a98f0877cb1a1b1450c6544a772da9fc9cn/a Quakbot