URLhaus Database

You are currently viewing the URLhaus database entry for https://strikingcvs.com/imtl/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635630
URL: https://strikingcvs.com/imtl/?1
URL Status:Offline
Host: strikingcvs.com
Date added:2023-05-17 13:06:10 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:22 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 days, 8 hours, 9 minutes Poor (down since 2023-05-19 21:17:46 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Eicsteo.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-19Unplnpgg.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-19Xeqfyt.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 25.42% 
2023-05-19Yknpyo.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Vpjqucah.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Ufkwhyq.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Rrgus.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Lgup.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Igezf.jsjs 5cdea75083536b05d4ef8a9433eac1bfff9df9d3341917503103df443fe10f1en/a 
2023-05-18Refiqc.jsjs 94482ada3a27f9e8cf8f7b554597969eef03e0593d496ba95205fdf735ed010an/a Quakbot
2023-05-18Rwurojlp.jsjs e0a76560e4dfa1a02a0ed9070737950e644f0b851388f7a580a8c384ba1ae3aaVirustotal results 28.81% 
2023-05-18Habobxj.jsjs 27d3fa3ffa307f97bc3047f15898d338734929484e224f43ab8740c710601a78n/a Quakbot
2023-05-18Hunq.jsjs 5f98b59055620e884f40e504321e65af6a6ff2e7eff1035ff136dc57e98e0cb1Virustotal results 25.86% Quakbot
2023-05-18Nujfto.jsjs a3a82b0e5a194f3c627df166b34ee132214dd6dd7f04b7a684d1b93af75f7591Virustotal results 32.20% Quakbot
2023-05-18Gkdazs.jsjs 5b081d8987954ca182f1f9c83eb5c24851ef6647e29f84c5fde150d826531e53Virustotal results 26.32% 
2023-05-18Tkrnqto.jsjs ecb53b7bd1821908e3358a50f35b5cc1aa92c43f7c190eaa7e0e473ca199dfa6n/a Quakbot
2023-05-18Fmvyobfs.jsjs a4fb26b40f74df15f85f6ee98f0faab524e9434e8469ea400fb9e1d4a53e6505Virustotal results 28.81% Quakbot
2023-05-17Myquqx.jsjs fab89deda2e8de1afcdf4d43b713652dab42ebcad6b4eddcd3b225188a7e3078n/a Quakbot
2023-05-17Pquou.jsjs 2683122550edbc50a5df311f2d51a511e7f980332b26d307f6ed2babdab38325Virustotal results 21.82% 
2023-05-17Yuabkc.jsjs 13c75bb7b88d3903fbb5263103d8e12f736ce24e98fc6397eb0286451317c087Virustotal results 27.12% Quakbot
2023-05-17Kagrsdms.jsjs fcddde4aefcc392bf143eaab986f85fa9fea69d7d232194ecf6c3080b8b60a1fn/a Quakbot
2023-05-17Hayfm.jsjs 784d0c23a7299fe8f5a79ce4f83765cd48535cf1afc25d542a0f854f8049d149Virustotal results 27.12% 
2023-05-17Wpxnyko.jsjs 5c53fc6d6d29d37ae644bf3845ff851d6b03cd26eb5e411f93c26dcf018a4c35Virustotal results 25.86% Quakbot
2023-05-17Bfosn.jsjs 98e65224d86b8f3b2be7f45d6b5bc6711e25eba8a298bf06d24ad94bfa8b2089n/a Quakbot