URLhaus Database

You are currently viewing the URLhaus database entry for https://thephoolmala.com/eins/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635631
URL: https://thephoolmala.com/eins/?1
URL Status:Offline
Host: thephoolmala.com
Date added:2023-05-17 13:06:10 UTC
Last online:2023-05-18 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:23 UTC to abuse{at}namecheap[dot]com)
Takedown time:19 hours, 45 minutes Good (down since 2023-05-18 08:53:57 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nrpub.jsjs 4a91fb2765da3056fe04bf5254fac9eb72f1fb4f8026845d71ffe672d4daac8cn/a Quakbot
2023-05-18Kdvnuqr.jsjs 34d43862c3788ec764c7fb735ddcfc1f1712a66632a3bf7e8b83cadc98a6faacn/a Quakbot
2023-05-18Mywilj.jsjs 4ca00c819ac67574145c0664985afbfd757621b4809ec157f14d22108aeacf8dn/a 
2023-05-18Chlvberj.jsjs d7ee80c4c9f9a041e63b9e4a454dfa6c60dcb7fdd18ca658f2f92fc97f61d766Virustotal results 22.81% Quakbot
2023-05-17Aiykc.jsjs 23c7e26757364f19557ee494d86b6dfc1c19e076aee18974a5443ce434459b22Virustotal results 23.73% Quakbot
2023-05-17Kprbzzay.jsjs 404e30334a58830297758dd73f2fee67f6ed0ea8c6d7fa501d7eb809925d82fcVirustotal results 32.20% Quakbot
2023-05-17Fstw.jsjs 62497d1af3f04d7da40a34f39d4cb3b28e855a47c2507372bfa759e66adfa3f6Virustotal results 11.86% Quakbot
2023-05-17Qlxhomxj.jsjs 1126eb773737ce63bcc031813a3893e30dcc5b6a0f018496a3e0106fdf1783d5n/a Quakbot
2023-05-17Ovqqbld.jsjs a5f0035e2f6ab21d643775a304ea994d963bc0ad712a5ae1a9ebb1a5298f7adbn/a 
2023-05-17Toxhujzz.jsjs 33f33ebc5ae78bdbf3a9afc064c64f1121c0214e1305d5567232cbc8779ab8c3n/a Quakbot
2023-05-17Dnui.jsjs ed3b42a466d5debc63224e8439d69996fd4f174cfcae800ac31dd8dcb69c921dn/a Quakbot