URLhaus Database

You are currently viewing the URLhaus database entry for https://oscarmontezuma.com/irr/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635725
URL: https://oscarmontezuma.com/irr/?1
URL Status:Offline
Host: oscarmontezuma.com
Date added:2023-05-17 13:06:24 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:02 UTC to equipo{at}brutalsys[dot]com)
Takedown time:1 day, 9 hours, 42 minutes Poor (down since 2023-05-18 22:51:30 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nnuygb.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Wayvw.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Mchbub.jsjs e7f49414f48f60c02d3fd4666eed1990fa42cef22983a0353e3334308bb5a428n/a 
2023-05-18Ewiwmk.jsjs 621b5cf40077c9b8235e3525da2dea7b28a80029ac3f7ee7477d78c780f4b8c7n/a Quakbot
2023-05-18Noywtgmv.jsjs f39cee789a4050e31f3f61e2dae48c0b5328d480424a439ba3c06fdf7d12ba43Virustotal results 29.31% 
2023-05-18Vtrqm.jsjs 34af4640c3591095a1562606faa096b2cab669c17859f8b99df4321999b17373Virustotal results 22.41% Quakbot
2023-05-18Djmz.jsjs 83743f2158c1cfe6f65635d6a1c2aeec71545802940ab5e083fa9d3a98d650aan/a Quakbot
2023-05-18Vdik.jsjs a23cf11c2f986f5d2412a9c98d50dad0b0a02cd2dbbd6fdb1eb47c20cb7dd2bbn/a Quakbot
2023-05-18Rvkh.jsjs 403516fd88c6e48a70d5ab2c1e966024e8e46c5403dcaa8dbb3b56774715cf30Virustotal results 25.86% Quakbot
2023-05-18Ovqhjos.jsjs c6acb46e483e7792474a50acd3a7ad70626f538da57050c7153b3061376b4f02n/a Quakbot
2023-05-18Dtcf.jsjs cbc57ebccb343515692b47782246ac3ce19ae8ae335ddc9895810261d11cb663Virustotal results 16.95% Quakbot
2023-05-18Uwedfrnf.jsjs e4e514b57ab086485b47e1413c71a7e9bebc8c84c6615f90bf252d04c98fb5ebn/a Quakbot
2023-05-17Uotp.jsjs 98e65224d86b8f3b2be7f45d6b5bc6711e25eba8a298bf06d24ad94bfa8b2089n/a Quakbot
2023-05-17Ywuzbo.jsjs 03cdab834b6a7165627af8e82df4d52dde740aa3481625a88ef76e122b7b2894n/a Quakbot
2023-05-17Moha.jsjs 582d7260d0c9d28291c1a5741818450399bdb826da9dfa44e69657727548f4f6Virustotal results 25.42% 
2023-05-17Txuqq.jsjs 9d55c860ce682edea5933b6e9e441703b00b9880087fafd62ecedabf0665836dVirustotal results 32.20% Quakbot
2023-05-17Nxwt.jsjs 029b6f2d9cfb0a2a335c9b9377c1dac9e71206e55f6f82c7d3c0e2edceb9b734n/a 
2023-05-17Utgji.jsjs f3cf1988e5b288b64fc34cf15045d67a4fcd2c9c61549510e3df907ea1f61cf8n/a Quakbot