URLhaus Database

You are currently viewing the URLhaus database entry for https://todaycss.com/ooi/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635133
URL: https://todaycss.com/ooi/?1
URL Status:Offline
Host: todaycss.com
Date added:2023-05-16 22:01:10 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:02:13 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 55 minutes Poor (down since 2023-05-18 22:57:16 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Cnpgu.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Frbop.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Bjjtoluv.jsjs 8627702a9bef884467c024c43b3ecee24052d71f30d05bcfac9781ece5d0de95n/a 
2023-05-18Gyzt.jsjs fcd00b353c980d48983a4a2533eb482d632935a343b2034ea119d3a4a74f3841Virustotal results 27.12% Quakbot
2023-05-18Wfswdado.jsjs a3a82b0e5a194f3c627df166b34ee132214dd6dd7f04b7a684d1b93af75f7591Virustotal results 32.20% Quakbot
2023-05-18Moph.jsjs cfc68b43d74cf7d5fd05920f53d7e80393899308fd60fbcd60c8582770294bc1Virustotal results 29.31% Quakbot
2023-05-18Aojlhr.jsjs 0b3324b249fb9e33cb3970056ed6166b271c1f678d65d34cdff6079bbd95f2c5n/a Quakbot
2023-05-18Tuyjvi.jsjs 287c569bf794a7ec47dcd5f308d39f138b6b4b964ad50c335991038cafd9d476Virustotal results 32.20% Quakbot
2023-05-18Obsl.jsjs e82f04f537f593c6f5469d18db6332febdcd169b2dc920ed7619f9edab951f03Virustotal results 29.31% Quakbot
2023-05-18Gouq.jsjs 03cdab834b6a7165627af8e82df4d52dde740aa3481625a88ef76e122b7b2894n/a Quakbot
2023-05-18Pyxaaov.jsjs 8aa9df652c080c1ab6754cea7be1a61ae330512a5ddbc9af51177cbeb20da8e4n/a Quakbot
2023-05-18Acnekslv.jsjs c5b4c29787160ccb71f79ff6637aeac99008ef606c71a4b14629e1281f03f74aVirustotal results 22.22% 
2023-05-17Xdbkoo.jsjs 494e69eca209ceb575b3ad74ff164605bc99c57a7621108280f95412b64e0becn/a Quakbot
2023-05-17Maltykb.jsjs 1c8c07d6d5454652a85d1673775e071cb4068ca92c83d2e45e4cf830d85e56b7n/a Quakbot
2023-05-17Bneiahkg.jsjs 0901cf7055bc662e98c048f651a2daa00fc1cec5bc745c6a25f315d5c31dc4dfVirustotal results 25.42% Quakbot
2023-05-17Tqpws.jsjs 9dc74a47b57fcd85200f975b411792401c29e5d1ac2806f4efca47c4fbc00eben/a Quakbot
2023-05-17Rwabzgcn.jsjs 875bccb572b756073e35cf697abde47c18a8fc4156b093bd6d229ef766faed99Virustotal results 28.57% Quakbot
2023-05-17Ffmkqnqh.jsjs 611f39b0fe3d00c6bc886929f93aab5028192d0d7398bd8621b700c05e99dcc9Virustotal results 25.86% 
2023-05-17Yynbajfw.jsjs 62497d1af3f04d7da40a34f39d4cb3b28e855a47c2507372bfa759e66adfa3f6n/a Quakbot
2023-05-17Qwjw.jsjs bf5a82777f0b5c7acd81691da192946f150c8cf25c03f98bdab7cb321a527f88n/a Quakbot
2023-05-17Gnoi.jsjs 4936581bbac637ab502032a4465fcdb1ace03f91125b559093aab6e5470da766n/a 
2023-05-17Hbjsmiv.jsjs e76962650249be64a826e7020a16e009941cd5c6c0b08bc87346d1c62be42354n/a Quakbot
2023-05-17Ukiclwe.jsjs dba3bf6607a592db85368d89a751952d335b2b24265185ca1f92e117eeb17332n/a Quakbot
2023-05-17Cqij.jsjs eee5fe6c0880526fe881f916f486e1c3abb042361b9fa73d32f5e00438490006n/a Quakbot
2023-05-17Yskbhjwo.jsjs 1bf7a00481a8c8207611021e9b831492ed6e3c3fc6f6a6f95600868182518d0bn/a 
2023-05-16Nuxo.jsjs f0069372ff6d9af8a1e98ffad7d5e799b99bd477be186d1f406b515a761f8495n/a Quakbot
2023-05-16Kmimf.jsjs 8c95af026832db5bed9868e9b6a2e3b14acda3773536a76ee592e628f423f133n/a Quakbot