URLhaus Database

You are currently viewing the URLhaus database entry for https://worldtravel-trip.com/avt/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635175
URL: https://worldtravel-trip.com/avt/?1
URL Status:Offline
Host: worldtravel-trip.com
Date added:2023-05-16 22:02:08 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:03:44 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 23 hours, 28 minutes Poor (down since 2023-05-18 21:32:12 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Mxosw.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Xwuxe.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Weemydq.jsjs fe38571546fce56178ef24eac652a6bdb02adb17817e8381824c1e1039b5f642n/a Quakbot
2023-05-18Loxmzox.jsjs ced3c62c0b0eb34cebf34dbcc0ee8a52ffec9388cc383952b09c7aa421199a79n/a Quakbot
2023-05-18Gsphql.jsjs 229271acfd7face73c4919f8ae74ec7e9e3d276810827e045c7ee12baf2e75bfVirustotal results 30.51% 
2023-05-18Ckwthllp.jsjs 3ac894a6a388d20bc81ae5f8474ee788079f5036842b1542150a55c8fed2059en/a 
2023-05-18Gipy.jsjs f4fb9e206467712813d87a31c0ea3285bf1a5ad9658839ca77ac0a61dcbf0693n/a Quakbot
2023-05-18Jbdc.jsjs 5c57b539392768e2e9e8490f11f6528d81875b4aae44e11319d0a94af50b1f00n/a Quakbot
2023-05-17Tmyw.jsjs 426babf013bd614f1197dea8df2fac24ddfb79398b8310b46631885ec666eb54n/a Quakbot
2023-05-17Hycxzl.jsjs ad9d5d545cd208607067a384f752e68873813a4863a25840901805e6778a5f43n/a 
2023-05-17Tbbno.jsjs 1f3d3d34fcd02bfbd9eba7becc4eb01342dffb209af4971f9df25374411cd1a7n/a Quakbot
2023-05-17Shthqvn.jsjs 75203d83c417a2bcd9a5298c46ac9c2befe4e75e7e2c40722c7b8f59a2232c98Virustotal results 27.12% Quakbot
2023-05-17Djiav.jsjs e4a27492752db4f16d33fd2962a507bbf88d2a2714ae618f3dfa598bdb44db2an/a Quakbot
2023-05-17Gagnzhs.jsjs 95f993cc876a8c3aa072647ab634b4ef2df037d739e781cb6f6b4e90ae5d6889n/a Quakbot
2023-05-17Ocjz.jsjs 42046702c8332860c6d6224d63344bbd919246deac12c67a32bee542c7cde41cn/a Quakbot
2023-05-17Wxynjk.jsjs f4636e6f60cfbd443019b37f6f9019440598e4267de13e9c306cb332be1b77a4n/a Quakbot
2023-05-17Uzlf.jsjs 13383c9058fc9e4b8d38ce369955bcde73fa869e5b0bcd9610f5b0b9add67bd4n/a Quakbot
2023-05-17Rsjmxfr.jsjs 6d3871f5e6f7526a5788482c5d13c63a0915133d18f3a67587c39dadc9c11acdn/a Quakbot
2023-05-17Jnlp.jsjs 44d61d44dbbe5345f6a67c80983bd1c0c5148411be66eb8b6ee5f183b1f456e1n/a Quakbot
2023-05-16Uecc.jsjs a48676e4b560681e89466177cf16c3654d94f214dda6a1e729c848844ee55858n/a Quakbot
2023-05-16Inofdnhy.jsjs e5aa6cad483d4d1ee2d7033e4e1bc3f3677962af13180ea4d66ac023ad7cf244n/a