URLhaus Database

You are currently viewing the URLhaus database entry for https://zcubemart.com/oo/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635171
URL: https://zcubemart.com/oo/?1
URL Status:Offline
Host: zcubemart.com
Date added:2023-05-16 22:02:07 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:03:41 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:2 days, 0 hours, 42 minutes Poor (down since 2023-05-18 22:45:57 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nzhudel.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Qofw.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Fumatosz.jsjs 3b745a37a7389d6968c9cb70b845e7fba3985125e13778f57e823dafc84664c5n/a 
2023-05-18Exhkwjm.jsjs 7f96290dff45385bfd8340f07e433e56831a66a593d5472a2ef8da6d665f355bn/a Quakbot
2023-05-18Dkax.jsjs a99deed91507b2e0aa98b17753892aa733b12eed707f493c38359420a3a4f109Virustotal results 25.42% Quakbot
2023-05-18Ksraf.jsjs b3c3f0880fe1ebd5b9f5146a8164da0834ee29a37e5a1cd8e534efe15c786daen/a Quakbot
2023-05-18Dmbmtmi.jsjs 3c65c87cf0e371c576074e364d5d415f782faa5f2381909a0cd1d6d3e16b21a3n/a Quakbot
2023-05-18Nmwyxh.jsjs 1e96a7079b653386193018082948ee18ee1ca517dd96395eb46b4d5e30507b87Virustotal results 30.51% Quakbot
2023-05-18Zzggmj.jsjs 4779dbaf4f01d866b1dd6a2cdeb855c53a82951952ba41e9af73be849bc9116bn/a Quakbot
2023-05-17Zcvwu.jsjs ba7f993248a05baa4fc8af51ce3e8f89889e817065c4b964cb37bfc088ae75d1n/a Quakbot
2023-05-17Pzhiy.jsjs 24c2f222f6f2809f7c5dda15d789a41d9424dfce3714fe71bed9fbb0e077503en/a Quakbot
2023-05-17Wccpcl.jsjs cac584e2ff62f01ca51db682d0b6d32ff11123c3bc3b6a5e9794606ad51844fcn/a Quakbot
2023-05-17Iutoq.jsjs 9459a0cb6bc3dff0f7972ac6852fb2f11dace3df33eded8be946a0ca5f1160d7n/a Quakbot
2023-05-17Ttxjkbi.jsjs 11576558dbc9d3d67fbd0b206c96ab6c857735ca94cd062fe5a61a6817da2794n/a 
2023-05-17Wdmnfe.jsjs 8c07255ba4a92a6c28c30b64274b275233d7407a2293bbeea8d56a394646b8bcn/a Quakbot
2023-05-17Zkfd.jsjs af3f022c5035728130279bfdb3be54d4c56f4bdca48af08dc3025f960dd49746n/a Quakbot
2023-05-17Xrpcxwa.jsjs 4d4bd9e296bb73900779e69d09536a0ac52dc93cc60454b2a14a0d7426eff4b2n/a Quakbot
2023-05-17Mnkrw.jsjs 0ee260dee1a1bab71729a0cdba968ef6df09eaf81eb57d1f4bb76011065dd767n/a Quakbot
2023-05-17Ywlsq.jsjs 3e1645f373684b1c2e66b870f350d35dc14b1abf6189115fce5b9da1a1aa4a70n/a Quakbot
2023-05-16Ctufdaz.jsjs cc7e9a0a0152efd97ef85aae50a5899dcac890168792c843f45a688606d39394n/a Quakbot