URLhaus Database

You are currently viewing the URLhaus database entry for https://unlock26ch-access.net/amu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635160
URL: https://unlock26ch-access.net/amu/?1
URL Status:Offline
Host: unlock26ch-access.net
Date added:2023-05-16 22:01:20 UTC
Last online:2023-05-17 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:03:30 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 0 hours, 44 minutes Poor (down since 2023-05-18 22:48:12 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Rmvkkk.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Nbeuliym.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Newfish.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dn/a 
2023-05-18Qgewm.jsjs 80b600e570c8d85aa7ca9bb34c921ea47502be7412ed43d82c86c186c7614532n/a 
2023-05-18Ikcnz.jsjs 8aa9df652c080c1ab6754cea7be1a61ae330512a5ddbc9af51177cbeb20da8e4n/a Quakbot
2023-05-18Xjxtpu.jsjs 8ef706183443d30910cb1d411aa36e657e86119ff849b6a9edef4125b752bb92Virustotal results 28.07% Quakbot
2023-05-18Oqcmz.jsjs 2ae770725a34857b3a2ff3821341d0b0363c401b4588d1bd1ce75048f2b83a18Virustotal results 25.86% Quakbot
2023-05-18Dchsyj.jsjs 8f29c702a43f99c1cfc18167ff61035ac4068757aba92e0eb5e9dde5ad72a0cdVirustotal results 31.03% Quakbot
2023-05-18Spbnbgp.jsjs 8a1f226245e5f15e87409d617437e6d102c8267d28d1bdb3f198a89620b090edVirustotal results 26.67% Quakbot
2023-05-18Vxiajhe.jsjs 59eafea575993fa2b9b1a5a60ec2852f5cbda6491cc6c163e79d91e7fc9b1d7eVirustotal results 30.51% Quakbot
2023-05-18Qabubkkv.jsjs 6f1a5f81c661643e1367ba7f42de50ede7d8841c0eb4bd7e13f5922b8a539766Virustotal results 29.31% Quakbot
2023-05-18Bqsgpf.jsjs f744aaa7347e22e22b0047605341e57c431a9dbcdd028ca5713a221c51107aa1n/a Quakbot
2023-05-17Onmp.jsjs 9f83e5346339db98db754ee60a6d9de3db2ecaf650f4590c2a11ad9e484c46a2n/a Quakbot
2023-05-17Qbrla.jsjs dc2082d0e27eabe3ed96fdbecac723d76fcbb6897709edc0b6e8a7a9a9ef177en/a 
2023-05-17Kgdnw.jsjs 8c854caf958691cbcce8d6a84edd87a8ead04c306a6a625c058d479d3b472059n/a Quakbot
2023-05-17Ielecqb.jsjs 12551eef6e57f08df39d1185caa198cce871f9b27d1fb58cd74228fc3a949b99Virustotal results 30.51% Quakbot
2023-05-17Oivd.jsjs b5992b77eea93b7005e9637b010d0dd51ae9310c87bea9dc6eb4610e2826d1ebVirustotal results 24.14% Quakbot
2023-05-17Qoeolgwh.jsjs 3ff223428a9d2b7b897fd823e4add6ae4cc119c86e47eb073bdbf5a578a17226n/a Quakbot
2023-05-17Ijnkzfwz.jsjs 38158794f34f920ddf3cc1bd5048a2d8be22b550ea27c09a0c746d59e22b3fc6n/a Quakbot
2023-05-17Qhqw.jsjs 444da53b0611f30b643dacaf2403ae5435ec5019883a06ad3d9f2c4d59e7d8b4n/a Quakbot
2023-05-17Xhliqei.jsjs 793f3bc3e9b94c086265d4d9f7c780c6e4304d433fea66a071a8c108421f6f23n/a Quakbot
2023-05-17Ckuodfuh.jsjs 2aeb4bba4e8810fb1293fbde73b09917bfcc3fa6da22829f41b6d32cf4d027den/a Quakbot
2023-05-17Uynldz.jsjs 9844f7eefb15648182e47bd1ada6c4af892aad7076b73aa49118b612d6c2713fn/a 
2023-05-17Chpytdt.jsjs daf722163b7090a0c37466f5ae12b265f85880baac6756e0fc8a4c35f006cbaen/a 
2023-05-16Iozngxhm.jsjs 567d9c1d706ce133bc266770a34350c02fddd3ddb82ce5f404c7288665e7d4dfn/a Quakbot
2023-05-16Fbwqd.jsjs 2af9ea6db9f887e24817d904970b29e02e6c10f8c0ba851f8df0bcac37f181a6n/a