URLhaus Database

You are currently viewing the URLhaus database entry for https://wiseestimating.com/rui/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635168
URL: https://wiseestimating.com/rui/?1
URL Status:Offline
Host: wiseestimating.com
Date added:2023-05-16 22:02:06 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:03:39 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 0 hours, 2 minutes Poor (down since 2023-05-18 22:06:25 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Tanpgit.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.33% 
2023-05-18Ctlfzgy.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Izbirz.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Koarm.jsjs 9b53168cab07922f9b504b1d175d9766a65fb7a77adb7e1c0a8fac8c276cd9den/a 
2023-05-18Oeqflfw.jsjs 6a36fcdbced70acfd047d3132e249ef81960cf97f62f9e391e672db0ecd19f13Virustotal results 27.59% Quakbot
2023-05-18Ncelzq.jsjs ee8f7825f5b87fbdb90f5bc8eff0cfadc358c64cfca2dcb37acfd398d5b2f201Virustotal results 26.00% Quakbot
2023-05-18Jnuvv.jsjs 74e7f951fe5dcd84fa5c570a1b2e27991662022a85a90f8f38cff80d462e8541n/a 
2023-05-18Srqvyjck.jsjs 076515d52f5219c37701ac4b38e72e4f6a809dffce463343615c3fb079c9ec89Virustotal results 26.67% Quakbot
2023-05-18Vbkgm.jsjs 0857b5e40844024689620ed0e9d9fbef8b9b295f54e11fba7dd9693f59ce40fdVirustotal results 27.12% Quakbot
2023-05-18Oqpcbpqm.jsjs b76a46e9b0db483e342c390f25663222fee2e67cb7670205636c7ee748850b86n/a Quakbot
2023-05-18Sjog.jsjs f6bf73aa768753f4379e2df6f0094dda46beb48b879c76c983896434f67c0ab0n/a 
2023-05-18Impqs.jsjs 4de2124d922958dc3b36346c1906578b79f12a6388ef771a7f8503c21e30af78n/a Quakbot
2023-05-17Enptdx.jsjs 928455b0e6b3a04da2d4fc9cc17de42c52ae2a640937dcbc9a048f76050c138eVirustotal results 28.30% Quakbot
2023-05-17Fuixwcqt.jsjs 8a1f226245e5f15e87409d617437e6d102c8267d28d1bdb3f198a89620b090edVirustotal results 26.67% Quakbot
2023-05-17Duycdlgd.jsjs 8deae0dc00f63d06da4b8491f06c909682b192af1c7ae4467703241c34a509ebn/a Quakbot
2023-05-17Ovtwfwkl.jsjs 7100bd0704b52e63e4581b308b07b43d48da5998a03a3ef43b8e78bf0d855d17Virustotal results 25.42% Quakbot
2023-05-17Qaagyi.jsjs d112f357338680817dc9cfe7ce64d7ab03de74008f16c43f1ef94b38bd159af8n/a Quakbot
2023-05-17Syqjm.jsjs c5b4c29787160ccb71f79ff6637aeac99008ef606c71a4b14629e1281f03f74an/a 
2023-05-17Htxoxjzj.jsjs 9a8083ef127004e2a3fd6d38ac13339555b0e82a7347cc9a1aaa97c8dda4041bn/a Quakbot
2023-05-17Vjschku.jsjs 91a5198c948c77a1f4e846013f6bb7d2ff376ca399e58f825e90cfbaf5c3c773n/a Quakbot
2023-05-17Amar.jsjs 2bcfa18abd43a13842065f759d0f952c9c4f0d901f81d306b4a04caede2b3303n/a Quakbot
2023-05-17Omqptmsm.jsjs b846c58cc51f01bca9dee50d3bd864516f741673040685ddff5e2192db395d7fn/a Quakbot
2023-05-17Fbocj.jsjs aaa3b0c11dd1345017775ec0c8769bed02f601044ed66bb795a5c4711d606f6bn/a Quakbot
2023-05-17Izwzfd.jsjs 9a3234bae90ecfc49d98ffbd270e16871cf01525d6d75d1c1131e62bfb5f07ben/a Quakbot
2023-05-17Pciiter.jsjs daf911959577a07f7b400de0b39a51a2471f95d52e3ea8bd38d106e4bb5eab42n/a 
2023-05-17Itll.jsjs 0cafb955a406d4280b8fdc31694c7519bc3af124a832ac5473d6d894ae00030fn/a 
2023-05-16Qlqgc.jsjs 2d56adcbd030b5dae83152775aa51c05af8d59a52c4f116ec31418a2364fbc21n/a Quakbot
2023-05-16Uxwdyacl.jsjs d522c309c74d1e7d5f867b451bcb7f88cfa96f7920cdaa84170f9e18538d1620n/a Quakbot