URLhaus Database

You are currently viewing the URLhaus database entry for https://lokhandwalaminerva.com/suc/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635716
URL: https://lokhandwalaminerva.com/suc/?1
URL Status:Offline
Host: lokhandwalaminerva.com
Date added:2023-05-17 13:06:23 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100117225 created on 2023-05-17 13:07:15 UTC)
Takedown time:2 days, 8 hours, 6 minutes Poor (down since 2023-05-19 21:13:53 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Qlhiya.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 25.42% 
2023-05-18Imfpl.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Fpqenjc.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Sjphkaxe.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Ojnsn.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Endpk.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Retui.jsjs be8e01f54a810d406fe3d1485f3fade7fde7af7490a1a22e929c060a0e601c46n/a 
2023-05-18Jaeao.jsjs f252bb947741e263a585e14d04e2ccd38b535351fa818233c9ab294b4b174275Virustotal results 28.81% Quakbot
2023-05-18Fwpg.jsjs ceb34fba0cd428a9dffee10f6b9c5857bfe8e363974adecbd1c42b994a5bb36cVirustotal results 27.12% Quakbot
2023-05-18Byodqyw.jsjs 6730ba9eb12acff08b5c019bd8587f2cecef533f14a7ca9fc80e7ed001bb903cVirustotal results 30.51% Quakbot
2023-05-18Hetfpt.jsjs aa49eea2c5b828df4f85742d3d76bc365ee6c18721795dfe567bd8be0b360d61Virustotal results 28.81% Quakbot
2023-05-18Pksgwvag.jsjs f1cd10870a25ff5450774a8498966cb5bddf350a269b79fee66a198f6cf3b7a6n/a Quakbot
2023-05-18Mhzr.jsjs 07903a989b7e8631bdf7709c9f662e13388037ed84e2a225ce9707ff6d5679a7n/a Quakbot
2023-05-18Ghhotg.jsjs 5c2f413b69f9b93e5bf828d8c4219af88afdfc9d6fc5d04d749815dc66cd664bVirustotal results 33.90% Quakbot
2023-05-18Owwbcp.jsjs 72c9727d22512473f4aa27d93e0c15ae33a95784d9804b057275d0d7d8b0a361Virustotal results 8.62% Quakbot
2023-05-18Yeqvul.jsjs de40c651da56945e6aa4f1adecf9ca842f4b2c630f3e1ad45c2c02952d4578c7n/a Quakbot
2023-05-17Lwfy.jsjs 6a36fcdbced70acfd047d3132e249ef81960cf97f62f9e391e672db0ecd19f13Virustotal results 27.59% Quakbot
2023-05-17Rkrds.jsjs 8ee5d86b74cd803753d211be4c64578d8d39e7dd487d114bdbe044505063bb7en/a Quakbot
2023-05-17Suva.jsjs 582d7260d0c9d28291c1a5741818450399bdb826da9dfa44e69657727548f4f6Virustotal results 25.42% 
2023-05-17Rzntmve.jsjs ef1c6b9ad4a7758ef25a4557fa7bf0a20ab6dd57c36474a91ef75620edd0974dn/a Quakbot
2023-05-17Vpockjj.jsjs f14437be247480b6af38f3ccdd4ba46e6e55eb7b3d706b8df711f63558b8703fn/a