URLhaus Database

You are currently viewing the URLhaus database entry for https://indigohomes.com/ulu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635742
URL: https://indigohomes.com/ulu/?1
URL Status:Offline
Host: indigohomes.com
Date added:2023-05-17 13:06:28 UTC
Last online:2023-05-19 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-19 01:38:05 UTC to soc{at}sucuri[dot]net)
Takedown time:2 days, 7 hours, 0 minutes Poor (down since 2023-05-19 20:10:40 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Dbyn.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 25.42% 
2023-05-18Hxsbig.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Ukfhgto.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Zijkmlu.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Rcqox.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Tfdwoj.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Jgjtu.jsjs e6e426852141021f9dc03b865f25af983dcddad41350ce49dd95bc8573e9e7d1n/a 
2023-05-18Ujoncwb.jsjs 05dab37be019900d575f8a51485f2baecb4fe212712970c486fb711a173c6290n/a Quakbot
2023-05-18Elkozve.jsjs b4b9340a057e2f27555df973e95af7d75b991cadbf943c5f48de2cbda1e3edcdVirustotal results 29.31% Quakbot
2023-05-18Tcay.jsjs 8deae0dc00f63d06da4b8491f06c909682b192af1c7ae4467703241c34a509ebn/a Quakbot
2023-05-18Gavubfpl.jsjs fb2bca8ce3aa4207fc636e9ebc34bb47cc0d9b6a233352bff3b6875b6bedce3dn/a Quakbot
2023-05-18Zjcrbq.jsjs 3b367e99561731587beb5622ae151a88c15c2153723768a743a9b7f635cf1303Virustotal results 30.51% Quakbot
2023-05-18Dyjcsc.jsjs 8b2b3c3498bea970b5883a908b36e4437b9809a010cf2df44004264d33d66dbdVirustotal results 11.86% Quakbot
2023-05-18Ocduex.jsjs 9695d2ed6261eeebd78cdc70e45105cb68ff36705197941a93e942a4f861ab3eVirustotal results 25.42% Quakbot
2023-05-18Ojkma.jsjs ca42f27ebd7d4d5472c9652e26b5cd7d9f089e838ea85a8ac5f1c51b37e83e30n/a Quakbot
2023-05-17Tdaahoi.jsjs 47838303934003e958511bf93e4b40816c144d7ddb6c99ad7cdda7145ee5dcf8Virustotal results 24.14% Quakbot
2023-05-17Rksjz.jsjs 170ceff8d051e5addeb6beb1128383fe814b7b40738b54c0f99409de5ccba2c6Virustotal results 25.42% 
2023-05-17Qtkuaoz.jsjs c1064ed6356f294c6981938454ee3a3712e5e63930c1554a3c1602eacbd6554dVirustotal results 25.42% 
2023-05-17Umpzmtf.jsjs ce5efda576bdfd577cb85bba27c1785787f37d30869878530f7249504d45cf69n/a Quakbot
2023-05-17Rwpyad.jsjs 5058b0ab18a174398413798e655e1f00408418493c371ea109decdfcde2e1608Virustotal results 32.20% Quakbot
2023-05-17Seyyu.jsjs 9be436ae8d8612af572358c0394b27e9c751e6f50b2597c2b7ae636e99088255n/a 
2023-05-17Pktoxv.jsjs 9d9924b0f0e33e1b74db34d25035395c2f29b1c29926ab16bfec2e29f30c8b81n/a Quakbot