URLhaus Database

You are currently viewing the URLhaus database entry for https://sumbercuan.org/aau/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635118
URL: https://sumbercuan.org/aau/?1
URL Status:Offline
Host: sumbercuan.org
Date added:2023-05-16 22:01:07 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 09:45:10 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 0 hours, 38 minutes Poor (down since 2023-05-18 22:39:42 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uldtt.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Spfr.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Xhjuzcem.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Zzeifk.jsjs 457e5c34f788ec65362304360350292e8f1435a1dbf8b2414eaa4b31ec85f120n/a 
2023-05-18Enphup.jsjs 86fa62e0346304f7f35a32db756544d5f0b031a7794b54ab9008570bd7ef65f8Virustotal results 22.03% Quakbot
2023-05-18Xyfgwaj.jsjs 3b3714312b9a47880e50308268338b4ce72011e082b2bb4bd94f2fbe7f738e56Virustotal results 26.79% Quakbot
2023-05-18Lyilpb.jsjs d306257143ef32e3f924f2886ed8c92b3dadea9e12e458ad402e9456a2e61edfVirustotal results 24.14% Quakbot
2023-05-18Orjtrobc.jsjs 4ca00c819ac67574145c0664985afbfd757621b4809ec157f14d22108aeacf8dn/a 
2023-05-18Ovtdbk.jsjs d188bb106c47296a6f358dc69226ce3c9b48abe1399e7cf924fc4afa813b1505Virustotal results 30.00% 
2023-05-18Ltqdrdwb.jsjs 24579cbeb7c33196bff853d67ce422776e45c942b057519eb6a6c453ed30ac62Virustotal results 30.51% 
2023-05-18Kgxosylc.jsjs 3f14bbee3c8ce3a67b5dfc257b5cff8e6f131ed1b17c77a50e705cb44af1c616Virustotal results 22.03% Quakbot
2023-05-18Jhfxi.jsjs 6bf7410f1b32c7fad44030961607fb13ec400a2a008f5817485ba84c5c297175Virustotal results 27.12% Quakbot
2023-05-18Eawjji.jsjs 50ebb94dd22b6d976b5ec46e2aaa6756dd807058f1a4fe1497d72c4a355b3c2dVirustotal results 25.42% 
2023-05-17Hsms.jsjs 17dcb0baeee21444da6b254c7dcd1d98989c6a0c089b8d79530a2c2a83dc34d3n/a 
2023-05-17Hhpiuhob.jsjs dc2082d0e27eabe3ed96fdbecac723d76fcbb6897709edc0b6e8a7a9a9ef177en/a 
2023-05-17Cdgsatyw.jsjs 16fe8055701bf9e829e70c4811b31fc75aec4d03582697ab493fd530e84ac6cdn/a Quakbot
2023-05-17Ppwluza.jsjs 9a8083ef127004e2a3fd6d38ac13339555b0e82a7347cc9a1aaa97c8dda4041bVirustotal results 23.40% Quakbot
2023-05-17Kgmfeta.jsjs eecafdba553631375cb34761f4cf33cae100547238141bd641f76c3cb87700f7n/a 
2023-05-17Aggtvhz.jsjs d6cb8ae70d4f102ac987c9de47abc6d962e10fa9755d74ea54a68edb6173dad1n/a Quakbot
2023-05-17Lazz.jsjs 4cfd3cea6e5aacf340993648b46bbd6628953021cc5148be665b68de39755e98n/a 
2023-05-17Jdmjat.jsjs 929ca648e275308d0c6f4ef03dcb1062df0f3d88ee291f50bb3b3dac90c0fdedn/a Quakbot
2023-05-17Wlmb.jsjs a751ba888c9526dbd8ab2e5bd23fac2590077c8d6bf7e6095f74e520ace941ean/a Quakbot
2023-05-17Wvzwp.jsjs 011188d744df6cdbb7b4ed05eafad200beedf171b3763b6c627c0ebbff6a6affn/a 
2023-05-17Tdtvbagy.jsjs a939567837f4ca48ec649c6dfdabe5c2d99798f982473ad1e233e92b5ba42fd6n/a Quakbot
2023-05-17Ijwoyc.jsjs f6e3eb0a6313ca75170acdaa4b6723b5959f7130951949cfe16145fef8287b21n/a Quakbot
2023-05-17Nboiqi.jsjs fe6eb671e9d5dd9d12fc5e6f57b6d2411f01c4c2c131dcd9ecaf99a3d5b16dd6n/a Quakbot
2023-05-16Iwzpiy.jsjs 8cb7dc80f359dcd587f745f343e1832c610dcf721d629a3f9c56c9bb41d10afcn/a Quakbot
2023-05-16Ohpl.jsjs 41fa0231c0dcc87863305e23591cd0b3634e11e09af6f3e51e70757f29302ca0n/a Quakbot