URLhaus Database

You are currently viewing the URLhaus database entry for https://foodfitgym.com/mpts/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635703
URL: https://foodfitgym.com/mpts/?1
URL Status:Offline
Host: foodfitgym.com
Date added:2023-05-17 13:06:21 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:35 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 8 hours, 30 minutes Poor (down since 2023-05-19 21:39:40 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Kvbir.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-19Tbwkiv.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-19Gbwrzsxe.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-19Irasxl.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Zbgyqics.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Idnja.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Hxuehm.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Bnbk.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Ivmnn.jsjs 4791f62eba9a99cb4448c74ce0a317e091fde5e790aaaf115b0d2e0514814176n/a 
2023-05-18Lfsdk.jsjs 561eeabd5f230ff8d733b3aa53f761558b65f54ba6d32241bf0350b4e136b808n/a 
2023-05-18Qmqbagpg.jsjs 88c9cde337f3a1dcaac0cf20b1b30b985ee5b11e0bd60b3b768a3f70751105f9Virustotal results 32.20% Quakbot
2023-05-18Zzxji.jsjs fa6d3526e896cb3ecf22f942020f813ff05b231a0755ca03e5588b547131c9a7Virustotal results 25.42% Quakbot
2023-05-18Bahsrmlk.jsjs 4779dbaf4f01d866b1dd6a2cdeb855c53a82951952ba41e9af73be849bc9116bn/a Quakbot
2023-05-18Ttwdjk.jsjs b76a46e9b0db483e342c390f25663222fee2e67cb7670205636c7ee748850b86n/a Quakbot
2023-05-18Qgniad.jsjs 426babf013bd614f1197dea8df2fac24ddfb79398b8310b46631885ec666eb54n/a Quakbot
2023-05-18Mdkeroil.jsjs 4de2124d922958dc3b36346c1906578b79f12a6388ef771a7f8503c21e30af78n/a Quakbot
2023-05-18Dvtodsox.jsjs e29a41a9d60625c8b7ab2e66896cd279af26a9abe095095e8f71d39a518717dbn/a 
2023-05-18Eyxlunuz.jsjs 9992a7c1ac03c78d2395f55820f9ac6e7ddca51d747b443183c09f8f2395f2ecn/a Quakbot
2023-05-17Kujqqc.jsjs fb2bca8ce3aa4207fc636e9ebc34bb47cc0d9b6a233352bff3b6875b6bedce3dn/a Quakbot
2023-05-17Aheqcy.jsjs fd6447c1e9b59d7114534e32bd988bd00fb674bcecc4c3d958b096bfc06b4acaVirustotal results 29.31% Quakbot
2023-05-17Rjietcj.jsjs 98e65224d86b8f3b2be7f45d6b5bc6711e25eba8a298bf06d24ad94bfa8b2089n/a Quakbot
2023-05-17Yixp.jsjs 10f759e97a48df574fc941e1fdddf412b2e5a598d13829c47c202527d7d36ee6n/a 
2023-05-17Thvo.jsjs a9d658acf1c13639bef4615e65fcd8eaebd3b1d0c14ee826b7268e893878e5a5n/a Quakbot
2023-05-17Ciioahym.jsjs af1b94948c602627bf551b38dae50d6be3c349f5b15e7fe1d2a792e047809553n/a Quakbot