URLhaus Database

You are currently viewing the URLhaus database entry for https://thetuxedoshoppe.com/eaue/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635156
URL: https://thetuxedoshoppe.com/eaue/?1
URL Status:Offline
Host: thetuxedoshoppe.com
Date added:2023-05-16 22:01:18 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:03:25 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 23 hours, 30 minutes Poor (down since 2023-05-18 21:34:19 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nrskwfbz.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Lcflafjc.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Kqwft.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Qyhkuqan.jsjs eee919ac998485dba6690d0ef5b0552aaafb70340e5458dab6116b25ae21606cn/a 
2023-05-18Xnazzavn.jsjs c5b4c29787160ccb71f79ff6637aeac99008ef606c71a4b14629e1281f03f74aVirustotal results 27.12% 
2023-05-18Bujrbep.jsjs bc100a785f531874618920cd99c357dfc32c33cd59fc6b19856a94b41ca3f07fVirustotal results 32.20% 
2023-05-18Znjbrbss.jsjs fcd00b353c980d48983a4a2533eb482d632935a343b2034ea119d3a4a74f3841Virustotal results 27.12% Quakbot
2023-05-18Jotwdj.jsjs e82f04f537f593c6f5469d18db6332febdcd169b2dc920ed7619f9edab951f03Virustotal results 29.31% Quakbot
2023-05-18Mktwe.jsjs 66131f1f9028038c86ecf420304c739126694a6e99cbba38c1bc18ae9c448ddfVirustotal results 20.45% Quakbot
2023-05-18Bjpm.jsjs c321a1664d74da4f73b983c793c4059b38202d4116be2e9f53f9aa1d4320d830Virustotal results 24.14% Quakbot
2023-05-18Mmzkjjno.jsjs 3e31ea9bfd38c94deda13767d5f82b55906ac8a767e595d59f2fbc92588d23e3Virustotal results 32.76% Quakbot
2023-05-18Ajnjeh.jsjs fceef22558799ba34afb830f44f63ff2d0386112e3506a24549d220e7ab2f4d1Virustotal results 15.52% Quakbot
2023-05-17Biiz.jsjs 2ef6e700c619c1ace05075497393d8ac827d836ec052de9b6a71a0cdcd343141Virustotal results 24.14% Quakbot
2023-05-17Wwrxixyj.jsjs a569ce1eb1902d2edf7cffba78e832e764170e48ecfe81ac3adda07c5f42455eVirustotal results 30.51% Quakbot
2023-05-17Pofgfl.jsjs d4048bb4d8d517078d21db74a0238b8f0696dbad0bfb9cecbe0dad5e3a89bb47Virustotal results 30.51% Quakbot
2023-05-17Tgbczqx.jsjs 8f5bae7c3310650dc125b9223695f4a40a6d1394f6f6f9dff466a3e53099ba7en/a Quakbot
2023-05-17Wdfyn.jsjs ed4b4009ba340ee9369058f34b9f50d2cb0057933fa2033412123538dd6093ecn/a Quakbot
2023-05-17Bidojcv.jsjs 0eb9fa07ffbdae465ca7afa7b68b6b38311315046844cd6ac97c9e3b77d5fe99n/a Quakbot
2023-05-17Wrztt.jsjs 6cb675336525f3ee63666c008f21faa80acdb6e41fec92d7d75201b385880e2cVirustotal results 30.51% Quakbot
2023-05-17Gmwcsvpv.jsjs 3b413252866f0b4261ccf3b4972d86690f29353242c85733133be84940ad6fa3n/a 
2023-05-17Xtshme.jsjs d57600dee1dc34d42b5b1b87eedbdf89323f376a651768c75177bb6d788e0266n/a Quakbot
2023-05-17Gopja.jsjs 9fc661a71480809328e7de995849db76eb55bc63d86cb1d551de6d2814675349n/a Quakbot
2023-05-17Zympkq.jsjs 001dbc09ffa6d2fbf3edd6b7326ca788d5f58cd8aaa5a0b3048175b33bd98846n/a Quakbot
2023-05-17Kgzmzdwr.jsjs e1c2d4f14ca4d66fc16dbfda735c4e241f3843861bd645f3644301200cbc6be8n/a Quakbot
2023-05-17Pfxj.jsjs a362074508428124d140a5ffe7cd9929ea62302ab77d1b04566ca3b58f452d24n/a Quakbot
2023-05-17Drlb.jsjs f55a3e23a0f353375c580775066015b3f3d02b6bcebec462407156cb64186113n/a Quakbot
2023-05-17Rbgdwl.jsjs 43eedf4aa7f97eb88a40837e71711c99631591281985ba8138dcf2682f0f1756n/a Quakbot
2023-05-16Thbox.jsjs b8b4fa3c6d99c584fa58f8c52b71c48b4efd23cae3595f7fe1011571b631fee7n/a