URLhaus Database

You are currently viewing the URLhaus database entry for https://theman-cave.com/iee/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635120
URL: https://theman-cave.com/iee/?1
URL Status:Offline
Host: theman-cave.com
Date added:2023-05-16 22:01:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:02:17 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 22 hours, 58 minutes Poor (down since 2023-05-18 21:00:59 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xqyixgrg.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Inguriss.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Auqzzvga.jsjs a8bb61810435eb1076f718e186e18910d203a2a14678c379b326d4efb572d343n/a 
2023-05-18Eclo.jsjs 67878c5898e4d6118aea2d8059896ec493c2cb1b7f3bdc563068504a0bca9373n/a Quakbot
2023-05-18Urcizlki.jsjs a3b99e8c39ad9b207f02de2422a94864986aae304adc635dc0cda1b27ac9e322n/a 
2023-05-18Jwzvndec.jsjs 7f5bfd748f09cddad1977aabe48a77b4aa3281b4bc9ac685ca0e53226b92c107n/a Quakbot
2023-05-18Ebua.jsjs 32191ec86c3fda99957a4e78362b4bad01545ffe830b5b5c5c32ed9c92fc58ebn/a Quakbot
2023-05-18Gohfokm.jsjs 1d2471f7acbab8882ea6f628275c501f0f81e0aeab5ee16537702bd849e8ba6bn/a Quakbot
2023-05-18Lmra.jsjs e5e55c026d33a226eeaecaec0b1f0e887452329d55151ca363f093722745e770n/a Quakbot
2023-05-18Lfupal.jsjs 5ca41989b791311510cc85281b20f28cd72d2554b2a862f47d9a9ac5ba9a70f9Virustotal results 25.00% Quakbot
2023-05-18Yiogbrhx.jsjs 2ae86821ba6902bdc957f61f92f752f51c37b2620aa00688fc6affc9b9b6c9c3n/a Quakbot
2023-05-17Wpdjqteh.jsjs e193e117a9fdecfac181547ca4dadf85602bca2aad6bd2c6edeb2a25d45e9f91n/a 
2023-05-17Qfkg.jsjs 5b903308829f5c7410c0e53ec748a05a9e2205f4400bf2941199cf2223c0e1f7n/a Quakbot
2023-05-17Bwymbl.jsjs b1c5cdb6f87ad0c3aacbf479218ede289571b85d30eb47defef749332b52c806n/a 
2023-05-17Cioaizs.jsjs 0727eef30bd3d52541c3e05de818415c77f77ce68db06ea425431972136cf8c7Virustotal results 32.20% Quakbot
2023-05-17Hpfitks.jsjs abab065bf35d31ff71f44feed5659074ee381a93862817826b7b884996333700Virustotal results 25.42% Quakbot
2023-05-17Tweli.jsjs c2c29ea19d16a1a70e365c2161d223994c0610958fe527bfcb605ed47c4a4d44Virustotal results 32.20% Quakbot
2023-05-17Dqkp.jsjs 266bfb248bbfb5fafc879d0a26c731499ccb3de4c57b64ce4b3a3fc6f836b93bVirustotal results 25.42% Quakbot
2023-05-17Cgxqe.jsjs 02736e3801e700601d6212804b2d824ae4771d32fb369044887fdc9f2076ddfdn/a 
2023-05-17Oqawgg.jsjs 802f749b5a120b0e594f04debd8f1bf924eb8363b7fb163bad28031b8ef531a0n/a 
2023-05-17Zpezgn.jsjs 1bcc7d164914accaa9f8d483826af19245f74fce7669e11d38e8dcc75f474dadn/a Quakbot
2023-05-17Slog.jsjs cb35e8cd111c6af98bf12077feac432c6707db84acf7ef7798d0446e01e63773n/a Quakbot
2023-05-17Hbfqdw.jsjs 4bd34d264134af287eb3d551c3ec712e16a6ac498e3d6f3232003472b226859an/a Quakbot
2023-05-17Epltplw.jsjs 95c88efbd4286d34879d331e65accef335108524d5827f4ee7caa88470b68cb2n/a Quakbot
2023-05-17Mmvtop.jsjs 20be6b6ec18701d1b8ee0b5881c2ec8a649fe00847dc015c28679628a6536e54n/a 
2023-05-16Rwcj.jsjs 099eaef0e0f4aad6a1c7662efe8b5c3759c15e4d5f44f631a48a565b3f2b746fn/a Quakbot
2023-05-16Isymiawy.jsjs 8dedd1e65d901445037d92137ed46e97c06adf8114c683a46b18bfae499dfbe5n/a Quakbot