URLhaus Database

You are currently viewing the URLhaus database entry for https://unpropertiesltd.com/deui/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635134
URL: https://unpropertiesltd.com/deui/?1
URL Status:Offline
Host: unpropertiesltd.com
Date added:2023-05-16 22:01:10 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:02:28 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 29 minutes Poor (down since 2023-05-18 21:32:18 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ljpofgxr.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fn/a 
2023-05-18Ridcryeu.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Tjplph.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Mtjl.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcn/a
2023-05-18Yvgaww.jsjs 7f5092d0b223ae713b6ead45d62c1c63d910a500fc960aeae16e1a1073355c86Virustotal results 25.42% 
2023-05-18Kozv.jsjs ba0c34e538207bb899f624292efada218b4202e276606cdaed6e258bd29572b4Virustotal results 25.42% Quakbot
2023-05-18Fsfbult.jsjs 42b8297467af3118af88bc8bd71bc4b1cff09e2fdd17dd631cda319c5c4cf592Virustotal results 24.56% Quakbot
2023-05-18Nicx.jsjs a7a7249194b741b44bab1befd74e783ba57af2f211b597961892dcbe975544c2Virustotal results 30.51% Quakbot
2023-05-18Jebkupy.jsjs 77a97bbae92dc7a7845ded72bd28a849a3c41c2912628816d93ff4b9a27ed45fVirustotal results 32.20% Quakbot
2023-05-18Zpud.jsjs 9ac768cf3025869132bdb78aad3f4505cd8dd7e5ddc218e64d6645ba8db5e4f4n/a GuLoader
2023-05-18Gxotmov.jsjs b7a9d786648f1049f8c0964593b9fa3983e6066f5674ff98d438cf5ec9d592f4n/a Quakbot
2023-05-18Govlbn.jsjs 6730ba9eb12acff08b5c019bd8587f2cecef533f14a7ca9fc80e7ed001bb903cVirustotal results 30.51% Quakbot
2023-05-18Rzarl.jsjs 6bf7410f1b32c7fad44030961607fb13ec400a2a008f5817485ba84c5c297175Virustotal results 27.12% Quakbot
2023-05-17Dewd.jsjs 6c2bc2e984886cdc84fd988cc8504fd8737f22afe09cd972d52344c526d16d5bVirustotal results 30.51% Quakbot
2023-05-17Pwsvhmi.jsjs 00662b73e2bd3a971290d1314c7c89f0f6d0d7244ebb8fde1721be20fa50a8daVirustotal results 30.51% 
2023-05-17Yvuzrrh.jsjs 43783ef70654df6b8b4c8d132454112d675abe8da1b8cacb358490d7b2159998n/a Quakbot
2023-05-17Krkftiqn.jsjs bcf9e05bff1a4453dbe187a142eddb6857e41bbaf3869f7ddc598b6ddca0d276Virustotal results 26.32% 
2023-05-17Oglfi.jsjs 55ba4dfbf0eeacaace5287a51196c8d2e3c7ae79a65fd07a27fd6024ca40bc13Virustotal results 16.95% Quakbot
2023-05-17Zsli.jsjs 1187259a79f3d0fa43b025751bffb4506d955db2a1072f8e61e3707c5250edadn/a 
2023-05-17Lpaxgiz.jsjs 285384a5ccf94492475a9af926ddb24dc621f5b0f19df79f8ed7366ca130d544n/a Quakbot
2023-05-17Otvhetzg.jsjs b46255680738a418371fef3bcea4a6219e29db4c579f3d98891d48fb59e500can/a Quakbot
2023-05-17Nsan.jsjs 6be301a7f2c93af56155c9bea7a83696dc96b072d1156a68a0d127c587d71f98n/a Quakbot
2023-05-17Xqrb.jsjs a0ce426ec687aa31080cf605e2048ba6e072b4d21c95a4a529ae1a34776b1247n/a Quakbot
2023-05-17Ybvybh.jsjs 09108f945293032b2818813347d2b77b6bc5d27e5d27159b528bb175b6173424n/a 
2023-05-17Unrim.jsjs 1c3dd69b5da33d4d9cff9cccf5f0da7e676621450b542d21e2887bf3145edc01n/a Quakbot
2023-05-17Lrmva.jsjs 87507dd39470c521fcd9d18954a67fa0b470220503f8d22a056327fae14b6e91n/a Quakbot
2023-05-16Ahrvv.jsjs 8cdfa54731c12ee33ddf15247d90a2d3f4533f27d58e899020a19f615ede89d8n/a Quakbot
2023-05-16Qiot.jsjs dc45db474e11dd4dfecf67c94392b8daf15b5730b5402a1001f3e47bfc64483an/a Quakbot