URLhaus Database

You are currently viewing the URLhaus database entry for https://zl-partners.com/es/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635609
URL: https://zl-partners.com/es/?1
URL Status:Offline
Host: zl-partners.com
Date added:2023-05-17 13:06:07 UTC
Last online:2023-05-18 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:03 UTC to abuse{at}deft[dot]com)
Takedown time:1 day, 7 hours, 37 minutes Poor (down since 2023-05-18 20:45:33 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qvanqp.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Juztyh.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Lecgajm.jsjs a2222ce8d0e97a87df66504d71e8092a824ba19249764ffbfbd6854a741ba1d5n/a 
2023-05-18Pobpsnxh.jsjs 9b2f8c74295c1bedca1e85a34eca84634c652741d93c24d9c5586926552a77a5Virustotal results 25.42% Quakbot
2023-05-18Zltpo.jsjs 53182e2434b52d11490f911c908c6c23755d667fca1a03ac5d4be2cc9b0cd61dVirustotal results 23.73% Quakbot
2023-05-18Dhqdkfk.jsjs f91b22ef75c62115177abfa54ffc898319098f3de31ddf0b2a964dae96c3b376n/a Quakbot
2023-05-18Rdkw.jsjs 9be436ae8d8612af572358c0394b27e9c751e6f50b2597c2b7ae636e99088255Virustotal results 28.81% 
2023-05-18Apfkjg.jsjs bc08bfae3a441cb9485634aeda5f5ae4cbbe5e36cd98ce7b2812cd62ed4e5034Virustotal results 25.42% 
2023-05-18Qbbny.jsjs 285384a5ccf94492475a9af926ddb24dc621f5b0f19df79f8ed7366ca130d544n/a Quakbot
2023-05-18Inso.jsjs 5f98b59055620e884f40e504321e65af6a6ff2e7eff1035ff136dc57e98e0cb1Virustotal results 25.86% Quakbot
2023-05-18Iahv.jsjs 819c3375d47e95f26e1466039e2ff5a096837d0761bed7564c2366b094c8895bn/a 
2023-05-17Djbngk.jsjs 981c8836ca3485400bc8fa7a73067986d2347ba02a058d61f1ee31be71d09a3cVirustotal results 25.42% Quakbot
2023-05-17Eiiobce.jsjs 17da932080db984c8594c50184bd0cfde690ed29cc7cd73f3136474e2cae191cVirustotal results 32.20% Quakbot
2023-05-17Aborc.jsjs fcdd7c512aa91e5f6574a7c7ab77a118b9e1af5f2e3b502a5adb136508c4ba47n/a Quakbot
2023-05-17Jcisoiih.jsjs 8b2b3c3498bea970b5883a908b36e4437b9809a010cf2df44004264d33d66dbdVirustotal results 11.86% Quakbot
2023-05-17Itfcm.jsjs cd8a39cd43a8cbb2e0c04b201b7df230226fe2dd696ab5c20c9ecbb16cc723f3Virustotal results 24.14% Quakbot
2023-05-17Koeevr.jsjs 076515d52f5219c37701ac4b38e72e4f6a809dffce463343615c3fb079c9ec89n/a Quakbot
2023-05-17Gllx.jsjs e98ab08e4897807987344800297aa41a72fc207a57b0e89510243b3b8ad0e144n/a Quakbot