URLhaus Database

You are currently viewing the URLhaus database entry for https://dnaultrawash.com/reoo/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635724
URL: https://dnaultrawash.com/reoo/?1
URL Status:Offline
Host: dnaultrawash.com
Date added:2023-05-17 13:06:24 UTC
Last online:2023-05-18 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:52 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 5 hours, 28 minutes Poor (down since 2023-05-18 18:38:50 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Zxdmuyx.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Tqgirm.jsjs 2e6d1893b3e0b02ede04348680f0d03b549345cbd2a3a42c6540d3a5cb1a942fn/a 
2023-05-18Xlbeqvtp.jsjs 119865e21bd0f564ac17f9e36940d9360139b87392fa02dce3483f1a789ab4abVirustotal results 24.14% Quakbot
2023-05-18Alnu.jsjs c5cd6ca0ca7e79a3c24d0b2e608780ee8eff700153663539c8be58f273a24565n/a Quakbot
2023-05-18Skogsdo.jsjs 43783ef70654df6b8b4c8d132454112d675abe8da1b8cacb358490d7b2159998n/a Quakbot
2023-05-18Fgvsruum.jsjs 2878ea27fb0bf41510c5a442c350ea2d31a71ee4c1532dcabf74f79b9aa1b3f4Virustotal results 28.81% Quakbot
2023-05-18Apxyfxx.jsjs d67719607166b2f101544e674067b1d8a66a134620ce0e19794356da09e033ebn/a Quakbot
2023-05-18Wetuoriq.jsjs 0e6261c9c8d05c96074d71e8c45d5c3dbb78736803c84ec4565a0db8dd83510bVirustotal results 29.63% Quakbot
2023-05-18Jsvawf.jsjs 288d425513bcbc2368880669d2eb2f2b553edb8962acfb77e4a967d751235520n/a Quakbot
2023-05-18Uvbkrql.jsjs de6f6abaf1f51ebe11aa72a93d20ae00f34f5c801284d731e438dd854258ee81n/a Quakbot
2023-05-18Iazkshdu.jsjs fc087bbfa79c07ccc635f8a6fd0b89dea00fce47f2c8fdd18e9a29c72d8a3bd0Virustotal results 25.42% Quakbot
2023-05-17Vpjik.jsjs 8c4f0c45a34f4cd509c3354346e0db29fbbe4bd099e2b67de6abc88dde35081aVirustotal results 25.00% 
2023-05-17Lqqud.jsjs 245d8b4566da1f99cc5bba4998955421b38764ee0718c94a6fe8019674ccfcd1Virustotal results 27.12% Quakbot
2023-05-17Vrail.jsjs f7141b5e0f8768e0c1d39b6da886c311b1ba7a4a1db8d4efe2c936270bc2f0c8Virustotal results 27.12% 
2023-05-17Pebrbxxg.jsjs e2334bf18981148d6120cbe4ab94a09cd0bb833ae95e71955079aadd6cfc720dn/a Quakbot
2023-05-17Lpejda.jsjs ba4eb74cda0088a1269ede2dd12d974109f7b392ff522322070233d302cb3d01n/a Quakbot
2023-05-17Jgknw.jsjs e6823880248255f28dad73af6553cfbae133b6df9f78eff124a379d793265ac2n/a Quakbot