URLhaus Database

You are currently viewing the URLhaus database entry for https://wiseestimating.com/lpei/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635170
URL: https://wiseestimating.com/lpei/?1
URL Status:Offline
Host: wiseestimating.com
Date added:2023-05-16 22:02:07 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:03:39 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 23 hours, 24 minutes Poor (down since 2023-05-18 21:27:45 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uvahd.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Rntgfxo.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Inktyzu.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Ryhn.jsjs 569b94ae6e9101918add0cbef52c7d0516b8faf8e79f3273d7d102982c544c18Virustotal results 22.41% Quakbot
2023-05-18Uvyb.jsjs 34bf72fbc4370971ff89c72391aca2a8a5b37aac3f1cbb8f2ab5480a3df6ae0fVirustotal results 32.20% Quakbot
2023-05-18Drcx.jsjs 35c35c65a46137ab025bfda60be1ea1c10a10b9cae6e337415b9c7b2ebd3df3en/a Quakbot
2023-05-18Trlva.jsjs 2bcfc438cf9c0a4f72832a134f6709c7596645ff3d738abe3b2fd53250ed50f9Virustotal results 22.41% Quakbot
2023-05-18Zlgvsjy.jsjs 32b63b6f4ee01c7737a32e2bfd61aca2c688fdbd79e9455010a3a5506954ff0aVirustotal results 24.14% 
2023-05-18Eksulz.jsjs ba0c34e538207bb899f624292efada218b4202e276606cdaed6e258bd29572b4Virustotal results 25.42% Quakbot
2023-05-18Kdfuqh.jsjs 0901cf7055bc662e98c048f651a2daa00fc1cec5bc745c6a25f315d5c31dc4dfVirustotal results 25.42% Quakbot
2023-05-17Krlthq.jsjs 743cf712f367f3c69cc6bfc3a3734a66d19bef6e76aabcc6a8b97c534a3b5557Virustotal results 30.51% Quakbot
2023-05-17Bfrycc.jsjs 62046b91a066c98a15aeba46b02ff8ae453c2d23d8e39a7e7eb2fb4d322464cfVirustotal results 27.59% Quakbot
2023-05-17Ulpz.jsjs 6da4a8bacb02c6d1b3251c5978545168c0712fb14b5ec2731a867b73a3daeacan/a Quakbot
2023-05-17Cmoxtxe.jsjs 8fe6b80c39f345411e663560d164edb44cbf0ad7ba4914ba79f02bb403348f27n/a Quakbot
2023-05-17Lofv.jsjs 185a635c927d918ae74aea58092eb9ecedc06bed0129605f9c210f1a3ad2d63dn/a Quakbot
2023-05-17Gupe.jsjs 8ee5d86b74cd803753d211be4c64578d8d39e7dd487d114bdbe044505063bb7en/a Quakbot
2023-05-17Ubwnndaa.jsjs 3b3714312b9a47880e50308268338b4ce72011e082b2bb4bd94f2fbe7f738e56n/a Quakbot
2023-05-17Iwatfe.jsjs 351524db3d56c005860ef4fd4537dc2c5861469c3c10e549e1b43c1135c90750n/a Quakbot
2023-05-17Ypfcznl.jsjs e7819c94ae9e29fc01870b8a154889bf24f32b6e662d7d245b548eae01f58617n/a Quakbot
2023-05-17Vmwttyxx.jsjs 07abe725e2a88d740a2e5d9d77a61f6b6305ffcfd6a2f4a71325c8972ecb7d43n/a Quakbot
2023-05-17Agcscw.jsjs 61e4ae28accea60101e633b940f0f9b655436e238d58a0cecd9c8f355f2b8ed1n/a Quakbot
2023-05-17Jqrjhj.jsjs 1bfab94d626c6efcab5d317a0ad770b7ede14b2c5859ef1220222715d2567706n/a Quakbot
2023-05-17Iessiibq.jsjs 1b3c119cc893a24c3020940264048538d414d8695e23e83d4598f11dc601af20n/a Quakbot
2023-05-17Stgygzgy.jsjs 0626e31b9667e85693dec1c8c83279e887813da3b3e3adfa1790505faa675e5an/a Quakbot
2023-05-16Zqzg.jsjs b18f73cbb04a3d415c7e06c020880e398ad0dd44b510be02cf1e118d2726f9c4n/a Quakbot
2023-05-16Swgh.jsjs 0e5bed71702d3d85b6ff85e62923c20b6cd41e6aa9a2f14bab5fb27b345eb39cn/a Quakbot