URLhaus Database

You are currently viewing the URLhaus database entry for https://kosmengroup.com/ee/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635803
URL: https://kosmengroup.com/ee/?1
URL Status:Offline
Host: kosmengroup.com
Date added:2023-05-17 13:06:38 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:10:59 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 8 hours, 45 minutes Poor (down since 2023-05-19 21:56:10 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Btamh.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 32.76%
2023-05-19Wazvm.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-19Kzqbesle.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-19Kkbjzaf.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Qmhgcm.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Xfncoqml.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Svvanxjd.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Jacwaupz.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Bllbod.jsjs 0eaba15ab577cf3c9483477182ae842774b648400dbd159ba17e92102b8fdf7dn/a 
2023-05-18Xporiq.jsjs 48db39cd7c0e54ce481a9a5a086bbcb4488584e914b43948388b02b053f75722n/a 
2023-05-18Fpjesux.jsjs 582d7260d0c9d28291c1a5741818450399bdb826da9dfa44e69657727548f4f6Virustotal results 25.42% 
2023-05-18Npniihex.jsjs 356f8c2ebf3f6ab97ed37e1195e6ccc8d5441e37c038c0c09c7f481b5aa205den/a Quakbot
2023-05-18Ohuolgl.jsjs e8a4b575211295a78e536c4a374d5538f24470f6036d3a1e5ab52f149b6a5683n/a Quakbot
2023-05-18Lwll.jsjs 4ca00c819ac67574145c0664985afbfd757621b4809ec157f14d22108aeacf8dn/a 
2023-05-18Gsqxg.jsjs 58b0e516ec4c36b4a0582314a01bc968a5e3a7acce646abe2179ef5adde91a24Virustotal results 27.12% Quakbot
2023-05-18Lqxv.jsjs 88e1c48885e6e3ca5b9336e4c427b393b3ed8d986289d640404abb2cdf869689Virustotal results 22.81% Quakbot
2023-05-18Bflz.jsjs b243ce7f5b24e6eab35ff99fcc718064f5897388b337460b05226b50e50b7dfen/a Quakbot
2023-05-18Eztawm.jsjs cca9ae0f45d9d362a7e18d9f86ed7a18a1340c3f3d4811c7a2ddc658408bd496n/a 
2023-05-17Bxvsmhya.jsjs 3ff223428a9d2b7b897fd823e4add6ae4cc119c86e47eb073bdbf5a578a17226Virustotal results 20.69% Quakbot
2023-05-17Vskmzqo.jsjs d306257143ef32e3f924f2886ed8c92b3dadea9e12e458ad402e9456a2e61edfVirustotal results 24.14% Quakbot
2023-05-17Hobltih.jsjs 8290e44e2bd6431a3cb8fce93c83b97d4710c63bffe7f1eb93db3282ae17b5f6Virustotal results 27.12% Quakbot
2023-05-17Zwextgh.jsjs ce5efda576bdfd577cb85bba27c1785787f37d30869878530f7249504d45cf69n/a Quakbot
2023-05-17Jqnyznk.jsjs 1518f10a4a3e1bb0772544083dd21336675b9248d73c59f8dd75068406de1474n/a Quakbot
2023-05-17Jvvl.jsjs bc100a785f531874618920cd99c357dfc32c33cd59fc6b19856a94b41ca3f07fn/a