URLhaus Database

You are currently viewing the URLhaus database entry for https://safes-endocrine.com/ia/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635673
URL: https://safes-endocrine.com/ia/?1
URL Status:Offline
Host: safes-endocrine.com
Date added:2023-05-17 13:06:17 UTC
Last online:2023-05-18 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:10 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:20 hours, 11 minutes Good (down since 2023-05-18 09:21:09 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Woxzp.jsjs f16b3c48ca1ba324e53c48a72c3bc53329423b16779e1cd1d0d40447f39cfefaVirustotal results 16.95% Quakbot
2023-05-18Yjjm.jsjs 56e958c5170fa27748c823f1145b93644170f72706fd132b2dfeb286ccf1192fVirustotal results 27.59% 
2023-05-18Iuri.jsjs 21fe5b84a05703a96f7e89bc1831bd5ef93ce9c6e1afe08259006454a502ba59Virustotal results 30.51% Quakbot
2023-05-18Npiegb.jsjs a74b08fd8574636c900a77d9d50f0c7d91b058b6a82d501d33a366e1e7c3d343Virustotal results 25.42% Quakbot
2023-05-17Dyluloe.jsjs 9a8083ef127004e2a3fd6d38ac13339555b0e82a7347cc9a1aaa97c8dda4041bVirustotal results 23.40% Quakbot
2023-05-17Xxjnuo.jsjs 817e3087dd09d826cc20a0381d67784b264c51a854134ac760b9219f49d58f0dn/a 
2023-05-17Lctuweln.jsjs 2a38d5dd759f5e13e433429b8fbed42e9b1fa7de9f671bf87d0739862847c16aVirustotal results 26.67%Quakbot
2023-05-17Mzzsob.jsjs 6cb675336525f3ee63666c008f21faa80acdb6e41fec92d7d75201b385880e2cVirustotal results 30.51% Quakbot
2023-05-17Fooiativ.jsjs 2f457141989cd8db7267b3dd982bc3aca3c0d763161cfedf75384aaa9b27bfe3n/a Quakbot
2023-05-17Nuglk.jsjs cb852f121e9dc83aa982abacf01603aed7cf0dfd1ac5c52956539b688ad41539n/a 
2023-05-17Ijbv.jsjs a45416e3d9aa47760feeee7375be42c3748b04b0d9c6c573bf4db2cfa07929b5n/a