URLhaus Database

You are currently viewing the URLhaus database entry for https://thekingflix.com/etu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635731
URL: https://thekingflix.com/etu/?1
URL Status:Offline
Host: thekingflix.com
Date added:2023-05-17 13:06:27 UTC
Last online:2023-05-18 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:44 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:19 hours, 11 minutes Good (down since 2023-05-18 08:20:45 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ivghtsq.jsjs 3fe82998dbbd1b56d6f2bf670fec8d276ac794d97facd50002a2cae0c1f41b02n/a Quakbot
2023-05-18Pvkfj.jsjs 0e6261c9c8d05c96074d71e8c45d5c3dbb78736803c84ec4565a0db8dd83510bVirustotal results 29.63% Quakbot
2023-05-18Veag.jsjs e21d7ce5a24617b4a823482fea8b703cee1f434028f5ee807b3d77bcb4197988Virustotal results 14.29% Quakbot
2023-05-18Sbwun.jsjs bf6a2013ee6092e2d291a06d2f69e617b318a1e842a0d559b91fa1b8f8ea1a1dVirustotal results 25.42% Quakbot
2023-05-18Cfgwgrl.jsjs 719ff669cd7b0754e787346601124ede6c1238c49809ebd0d6b58a3bf4b5a9bcn/a Quakbot
2023-05-18Xxzi.jsjs 12551eef6e57f08df39d1185caa198cce871f9b27d1fb58cd74228fc3a949b99Virustotal results 30.51% Quakbot
2023-05-17Yets.jsjs aaa4050b504cc828d80b7057106a778bca86d9e00c674992ba5ee3eddf1db803n/a Quakbot
2023-05-17Jskacm.jsjs 56e1630e4d5a2e6b1c2e4e5494d4f0934129788140e2bb2894da4d50c48ece66Virustotal results 27.12% Quakbot
2023-05-17Sgxpn.jsjs bb118ed7175733d7b31163818a3948e5e35d0e3ab3627a549e93cf6afa196585Virustotal results 29.31% 
2023-05-17Agftsh.jsjs a2f17ffca655028bf5663349090771ded5e0eac6f65e71d0fc151816a2dc7342n/a 
2023-05-17Qnllrxw.jsjs 4de2124d922958dc3b36346c1906578b79f12a6388ef771a7f8503c21e30af78n/a Quakbot