URLhaus Database

You are currently viewing the URLhaus database entry for https://kapuas88gacor.com/rmd/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635737
URL: https://kapuas88gacor.com/rmd/?1
URL Status:Offline
Host: kapuas88gacor.com
Date added:2023-05-17 13:06:28 UTC
Last online:2023-05-19 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 9 hours, 26 minutes Poor (down since 2023-05-19 22:34:28 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Hxsrml.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-19Utavxl.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-19Khguguk.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Lspvqzd.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Smavcwn.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Nygwf.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Aflmpkfr.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ejpce.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Fxrqohn.jsjs 872f152fb783ebf8edce56db1f1560d51033e21cb0dd78199c964c2a02d91b1cn/a 
2023-05-18Nvbvf.jsjs 70cbe6d0639705257a62be9eb8da5151af27830bf379d05aaffea8a6d1f49b39n/a Quakbot
2023-05-18Ixkwzff.jsjs b11ddd3e32db780631dee2546f8eb8498cf1976976b4f9b6229279881aff3e12n/a Quakbot
2023-05-18Fcgqzzqo.jsjs 50ea4195ce44fd0c177d6c8bca4b2a4f34676b3b8cbddaa734fe11cf5a265f01Virustotal results 24.14% Quakbot
2023-05-18Eeuzee.jsjs 7b501e67649c8608b6333e95e174a2d3db77d745651cf4142c43e79b0e1ed927n/a 
2023-05-18Cthqzv.jsjs 51351bc77c5c23de367e4fdd74a87fd4ea6a100dd396c2f78dde57c715543f3dVirustotal results 27.12% Quakbot
2023-05-18Gpdmjs.jsjs c1460321f81f5ddaf0e6965fdc14511326240b2d261c1e2c98e92f73eb1accd4n/a Quakbot
2023-05-18Tdly.jsjs 928de378e1b8690de67deab709ed80da406ac542daf31e7c5859f02c0b9a4240n/a Quakbot
2023-05-18Aqcjxdcn.jsjs 456c54257858cdc9347b6b71444659a256ae3a000dc1c82298d0fc65ba890687n/a Quakbot
2023-05-18Aacsa.jsjs 9695d2ed6261eeebd78cdc70e45105cb68ff36705197941a93e942a4f861ab3eVirustotal results 25.42% Quakbot
2023-05-17Nfnma.jsjs db756aef0c52e6f31a7cb628eefe67b0cc7d656427dd2d71c87ecce62165b562Virustotal results 22.03% Quakbot
2023-05-17Vjgbxd.jsjs 3b521273a1f49f0fb7c2f4ea15df405e5c77af2e36c653ca0e352ada89db0c6bVirustotal results 27.12% 
2023-05-17Iijueb.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-17Czcgualb.jsjs 8deae0dc00f63d06da4b8491f06c909682b192af1c7ae4467703241c34a509ebn/a Quakbot
2023-05-17Dclj.jsjs d2087d9119d773d88b9ed612b2300de62865eab8a6dfbab02955c20d0bd11582n/a Quakbot
2023-05-17Xhbouwkx.jsjs 0e713770fa4e2a4f457544637a3e0172325fd23e5f1120cded0547dd2236f70dn/a Quakbot