URLhaus Database

You are currently viewing the URLhaus database entry for https://balgocburada.com/ve/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635720
URL: https://balgocburada.com/ve/?1
URL Status:Offline
Host: balgocburada.com
Date added:2023-05-17 13:06:23 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:48 UTC to abuse{at}ni[dot]net[dot]tr)
Takedown time:2 days, 8 hours, 46 minutes Poor (down since 2023-05-19 21:56:25 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Sqrd.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 39.66% 
2023-05-19Adtmpiwl.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Zalr.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Vfckdn.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Bxrwgvuy.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Mmoujlbk.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Wlweyiag.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Sxwnvbky.jsjs 6f2976acdd1ad7886fd27c680283b88b9b198ed6738fff107783fbfa70983cf7n/a 
2023-05-18Loym.jsjs 983c9fb0828b90c43eda528aaf767c2c7d4b71d59b86ad0d04461db11d91794bVirustotal results 30.51% 
2023-05-18Rmbqpq.jsjs 77a97bbae92dc7a7845ded72bd28a849a3c41c2912628816d93ff4b9a27ed45fVirustotal results 32.20% Quakbot
2023-05-18Zxslxi.jsjs e50fb972f8f78042286895b6d869daf014f5e8082e3c3989ca853daee780a6aan/a Quakbot
2023-05-18Kjjthcf.jsjs e5f9fc33236b5ba2988d71e8585b3802d96cde07263ae499ce6ac56cc9db183aVirustotal results 27.12% Quakbot
2023-05-18Ivfqnjq.jsjs 043c810fd7d77672928841fc44891531ce536c6b4cfb9a4e54529c20b36eecd2Virustotal results 30.51% 
2023-05-18Zqjvwx.jsjs b9a4b8691e7de63f6af1a61319d16827e3308ff248981ca1c9d815fee2a1b93bVirustotal results 32.20% Quakbot
2023-05-18Svwkf.jsjs cac584e2ff62f01ca51db682d0b6d32ff11123c3bc3b6a5e9794606ad51844fcn/a Quakbot
2023-05-17Clkgyd.jsjs 35a99626b0db91409ed1ac874964033c1490a20549ae611e95fa7f81dbd98d44n/a Quakbot
2023-05-17Fubkow.jsjs 0651c77d8fadac8f6e3798ca1534ef6af11482867d22cfb20df41d868c3cc727n/a 
2023-05-17Guozn.jsjs f33a199b902aff95c3dede5cbfe632298042593120c23bc925987f2dcdcfce53n/a Quakbot
2023-05-17Corrman.jsjs d25526dc27feb5e67f938d4b403a9dad1250e9bad80e8f4d66a22d696dacc328Virustotal results 32.20% 
2023-05-17Fhbvlu.jsjs 55958c9aef4b48e1d2648546d04249950dc900677dbaa6883bf95cc5db2df09aVirustotal results 23.73% Quakbot
2023-05-17Gbpcw.jsjs 94482ada3a27f9e8cf8f7b554597969eef03e0593d496ba95205fdf735ed010an/a Quakbot
2023-05-17Vcxme.jsjs 8f5bae7c3310650dc125b9223695f4a40a6d1394f6f6f9dff466a3e53099ba7en/a Quakbot