URLhaus Database

You are currently viewing the URLhaus database entry for https://bimskol.org/iol/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635662
URL: https://bimskol.org/iol/?1
URL Status:Offline
Host: bimskol.org
Date added:2023-05-17 13:06:15 UTC
Last online:2023-05-18 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:59 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:19 hours, 45 minutes Good (down since 2023-05-18 08:54:05 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Yxmtz.jsjs 683503e1ee6accf36b4e270156fa48982aeb9619157f07c35c1dbbfeb8a43e7dVirustotal results 29.31% Quakbot
2023-05-18Gvqnca.jsjs a581d1bc0926e4888a7d919a2ec529d51e03862bf784ac4cd4333e3df168d239n/a Quakbot
2023-05-18Pyhscabl.jsjs e78861a712a577b61558f7ea9878b91e974692081e5daa5f02dcb5ff1cdc359aVirustotal results 32.20% Quakbot
2023-05-18Gziplp.jsjs 7100bd0704b52e63e4581b308b07b43d48da5998a03a3ef43b8e78bf0d855d17Virustotal results 25.42% Quakbot
2023-05-18Ogdhmxna.jsjs 655729ffaa1d79b40a1df6017495f362432d5497a1c79b18220fdcc46d21f2aen/a 
2023-05-17Yejiq.jsjs a99deed91507b2e0aa98b17753892aa733b12eed707f493c38359420a3a4f109Virustotal results 25.42% Quakbot
2023-05-17Wwlyamt.jsjs b87903d0aa16eb59b3bd58047ae31f7e370cc478a7b6d952e262fe4e56abb4e3Virustotal results 26.67% Quakbot
2023-05-17Dwlivv.jsjs 09ae96eb664bab43c15f8208e579fc06cb4e92d817de28ade6659d138ca9571en/a 
2023-05-17Peltl.jsjs 2ffe30857db286ab5839fb47499480fff446371b3c1f8df2d8dde6853266f088n/a Quakbot
2023-05-17Mvpea.jsjs f0ba5660e9ba7e62c93207a7b6fd775ee56ae1fa8dfc2ece0f169a6e96076681n/a Quakbot
2023-05-17Yiaqw.jsjs 33f33ebc5ae78bdbf3a9afc064c64f1121c0214e1305d5567232cbc8779ab8c3n/a Quakbot