URLhaus Database

You are currently viewing the URLhaus database entry for https://neelikon.com/st/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635732
URL: https://neelikon.com/st/?1
URL Status:Offline
Host: neelikon.com
Date added:2023-05-17 13:06:27 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100117228 created on 2023-05-17 13:07:18 UTC)
Takedown time:2 days, 8 hours, 25 minutes Poor (down since 2023-05-19 21:33:03 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Yfpy.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-19Ineoqkyw.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-19Pwwuer.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-19Oddwndvv.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Qpqdwvg.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Jppi.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Yxmrqg.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Yywxflx.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Rhbw.jsjs 9b5facdf9deab5bc50ee638a09314475c7ddadc24b5dd33a91a37f4c9e61dabbn/a 
2023-05-18Nefdh.jsjs 9162c26ac66cb673664c91b6a22e788a008db7c2bd2b4a9b7788a47fe85f33eeVirustotal results 27.12% Quakbot
2023-05-18Xijw.jsjs 93bba231e08381a78fea4f6623a38ef11130273ca9bad59f5132b68797d90d23n/a Quakbot
2023-05-18Othvtcn.jsjs 872a8726044bc6afb068028c44ba1376f7a3a6835147e080a9c5b7de41d634afVirustotal results 25.86% Quakbot
2023-05-18Tdoausj.jsjs b45fa98328f6170801cd88be88f4ac670f2266e2ed383e78f37fdd5d860dc695Virustotal results 30.51% Quakbot
2023-05-18Pcnsa.jsjs 6325a36db9c4fb5af943871bce9ae9c80002f6d9379e71cd94bdefe0342b14f5Virustotal results 32.20% Quakbot
2023-05-18Pqhxha.jsjs ebe8f7530444ccce930ca2eb9bce9d1a8dc83786f22d231c9b0ecc1b37803d8aVirustotal results 23.73% Quakbot
2023-05-18Rems.jsjs f276da1a81b23b7f647bba9fedb53f4e8df35e0456b09c909184c6c45bcd9d99n/a Quakbot
2023-05-17Pwmzbbqz.jsjs ed3b42a466d5debc63224e8439d69996fd4f174cfcae800ac31dd8dcb69c921dVirustotal results 31.58% Quakbot
2023-05-17Dznr.jsjs 67ff580532af15d6457fe1b6aa59886c46bd5c72906c86b58aae1e7aab70fa3dVirustotal results 25.42% Quakbot
2023-05-17Xelqmlqr.jsjs 67c42e2dba1a888a502921f8497455eea4965e6a313718853b1782317b27c950n/a Quakbot
2023-05-17Ticwz.jsjs 817e3087dd09d826cc20a0381d67784b264c51a854134ac760b9219f49d58f0dn/a 
2023-05-17Ctsz.jsjs e8f221308008303d546d565fcb2601b794a95ce83d609f81b4629c5284a8547aVirustotal results 24.14% Quakbot
2023-05-17Psazvka.jsjs e2cd2a44ac9c613f289c14a9d30244223f9949818db49dc69c73a5efc442a948n/a Quakbot
2023-05-17Iunid.jsjs a357a8a9b62674cff6660b76659f4cd36ccd979d44937371bde57235d81c392en/a Quakbot