URLhaus Database

You are currently viewing the URLhaus database entry for https://thedesignors.com/ngm/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635126
URL: https://thedesignors.com/ngm/?1
URL Status:Offline
Host: thedesignors.com
Date added:2023-05-16 22:01:09 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:02:23 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 22 hours, 59 minutes Poor (down since 2023-05-18 21:02:05 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Cqckq.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Jbee.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Dxsz.jsjs 8311d0f32b09192ffedb89e05b1776fe0c083197e05bfc2627ca1e95dc2b3956n/a 
2023-05-18Flcmdsgs.jsjs 90854b60ab6b30c83f8839a6d1977dc7968771625bc4a6751d30fa1ff505912bVirustotal results 27.12% Quakbot
2023-05-18Dmixjx.jsjs 4df2da0e1a60159c49866a7e3899e305f80766c9bae6b676bf18955d4e2ee8ecVirustotal results 15.52% Quakbot
2023-05-18Qpjrzsr.jsjs 68e8f2f3d6612aa52ea6f93813be80d9984f0626bfb504047a29018c7e7748a5Virustotal results 27.12% Quakbot
2023-05-18Ttfkir.jsjs 819e1677a9b83e3e2c5f43d5b2dc0f2f54147bd8257c067505fb818330efc68an/a 
2023-05-18Rzykfqe.jsjs 81f0fe1ef9b350d79e5c368c2f73deec42c5a379bfbbe52f88c1c79ee481b5e9Virustotal results 11.86% 
2023-05-18Jlcqp.jsjs 8f547a495bc6e319219b5db2491f70ce4792f76b7770226d37be2b28fa5f79ceVirustotal results 27.59% Quakbot
2023-05-18Sjybijpp.jsjs 9a649ac76d537c5f4ceb023745e2fcb3a6ed8443c46ac1f2dbd7da98f0487deen/a 
2023-05-18Ywzfkw.jsjs 0727eef30bd3d52541c3e05de818415c77f77ce68db06ea425431972136cf8c7Virustotal results 32.20% Quakbot
2023-05-17Wdbogp.jsjs 494e69eca209ceb575b3ad74ff164605bc99c57a7621108280f95412b64e0becn/a Quakbot
2023-05-17Toogg.jsjs 1c527faebea66510912a82a4ece923294f74fa2947ce89b48b9b341ade828e1en/a Quakbot
2023-05-17Jqjp.jsjs 5fe1ce92222b0ef2d0fe599c26907689fbeb05acb3c14dcc9cd468d2db479a26n/a Quakbot
2023-05-17Hwotjrq.jsjs c977474e11ea0066144f719c48b4f2d5ae32da3a13eab7d64cb3433546b8d738n/a Quakbot
2023-05-17Upsyns.jsjs 5058b0ab18a174398413798e655e1f00408418493c371ea109decdfcde2e1608Virustotal results 32.20% Quakbot
2023-05-17Feshtyaz.jsjs dff43d93176f7f0b50d2b960680eb78be307c219d3a2f9b42d969390818a467fn/a GuLoader
2023-05-17Huyuhjov.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-17Sczl.jsjs 2971e245d875fcb96bbbbcff59e1a34e0490ae85f5e8abd688b28772bca0b30fn/a Quakbot
2023-05-17Ngtw.jsjs 80e7c48837fd914b4870f281b6c3af2c2c756cf4a8d21fa7beb21b96ac701bd2n/a Quakbot
2023-05-17Vlzklkd.jsjs 8eb126ec232a2ac0a358cd20d6272eb57ef46e2d073214010eef04c64d7fd669n/a Quakbot
2023-05-17Lezlqqe.jsjs 81a0e56d7fda309a5265046a3816d61d2a2ddaf8d881124eeeb1f9203058c659n/a 
2023-05-17Srbmujyi.jsjs c2342d8564fba9bcf0262381ba8ebfb0ebd819e3a3a2eae9e757ef310f598fadn/a Quakbot
2023-05-17Opjunh.jsjs 857c72857a7a2855be05f0546bdc192a952d5bda1dacbfb2c0d739745abe821en/a Quakbot
2023-05-17Gwmami.jsjs 8fa0a196a2b67fa38feb3926c945fd3d7291b2f0f89a3ec49ba370910f41228cn/a Quakbot
2023-05-16Zkqkkt.jsjs be0486568fdde3d505adbaef9b9aa1e361272dbd8c038cdad35207cd4a5a4ff7n/a Quakbot
2023-05-16Twfszq.jsjs 57d42d8f6e29b386090f7db65b0b43568bfd39d25a812ef718228c543d89f8b1n/a