URLhaus Database

You are currently viewing the URLhaus database entry for https://visaexpressbd.com/na/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635643
URL: https://visaexpressbd.com/na/?1
URL Status:Offline
Host: visaexpressbd.com
Date added:2023-05-17 13:06:13 UTC
Last online:2023-05-18 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:38 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:19 hours, 26 minutes Good (down since 2023-05-18 08:34:58 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nllfvl.jsjs 229271acfd7face73c4919f8ae74ec7e9e3d276810827e045c7ee12baf2e75bfVirustotal results 30.51% 
2023-05-18Wgjz.jsjs e29a41a9d60625c8b7ab2e66896cd279af26a9abe095095e8f71d39a518717dbn/a 
2023-05-18Yktkwuca.jsjs 09f9e4d8ef85ba407416a7d168207db81c2000eabea300624e17d81f58bd0b18Virustotal results 31.03% Quakbot
2023-05-18Ziiazn.jsjs 1518f10a4a3e1bb0772544083dd21336675b9248d73c59f8dd75068406de1474Virustotal results 23.33% Quakbot
2023-05-18Kymmicfw.jsjs 88f6a8cb20802cddd090c331d20f9642aed6deeda17214154bc2017f911d61c3Virustotal results 25.42% Quakbot
2023-05-17Aohx.jsjs fecdae98fff4b89aadb8c35ded8061bdaa126fc12f3fd482cbcecd53246c1c0an/a Quakbot
2023-05-17Iodztkvx.jsjs 716b277dffdcf3099c8c86e0198ddab7a5d55627de582e5b73e900db63fed67en/a 
2023-05-17Pupe.jsjs ccdaaebf2ae2ce525ab5ccf2b4d74cf6b58e7d9515c21c0d46e2b8e0709eefb6n/a Quakbot
2023-05-17Trtu.jsjs 42046702c8332860c6d6224d63344bbd919246deac12c67a32bee542c7cde41cVirustotal results 25.86% Quakbot
2023-05-17Fawfke.jsjs 1023d2a3febc48f033a53509d7c13ab44b981e38169392d13c7ad15e12b37515n/a Quakbot
2023-05-17Akqfva.jsjs abae955795961dc369ba3d41196f2f4238001efcff8a2dc429ababf4821ca7f5n/a