URLhaus Database

You are currently viewing the URLhaus database entry for https://jobs-sa.net/slat/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635817
URL: https://jobs-sa.net/slat/?1
URL Status:Offline
Host: jobs-sa.net
Date added:2023-05-17 13:06:40 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:11:08 UTC to abuse{at}nl[dot]leaseweb[dot]com)
Takedown time:2 days, 8 hours, 28 minutes Poor (down since 2023-05-19 21:39:35 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Wlhebgo.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-19Okeri.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-19Petlqlqy.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-19Ehrnol.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 25.42% 
2023-05-19Lszanp.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-19Njfmitg.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Welcyane.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Rxbxde.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Nlwq.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Lsilkvw.jsjs 4b156376828521158a3243211c252339ce206ef2e1086ea211ed62a9d35792dcn/a 
2023-05-18Ddyweaw.jsjs e8a4b575211295a78e536c4a374d5538f24470f6036d3a1e5ab52f149b6a5683n/a Quakbot
2023-05-18Soegsp.jsjs a99deed91507b2e0aa98b17753892aa733b12eed707f493c38359420a3a4f109Virustotal results 25.42% Quakbot
2023-05-18Kyyxdl.jsjs 9ac768cf3025869132bdb78aad3f4505cd8dd7e5ddc218e64d6645ba8db5e4f4n/a GuLoader
2023-05-18Kbuvy.jsjs 0727eef30bd3d52541c3e05de818415c77f77ce68db06ea425431972136cf8c7Virustotal results 32.20% Quakbot
2023-05-18Tiwgk.jsjs dff43d93176f7f0b50d2b960680eb78be307c219d3a2f9b42d969390818a467fn/a GuLoader
2023-05-18Orkezem.jsjs 17da932080db984c8594c50184bd0cfde690ed29cc7cd73f3136474e2cae191cVirustotal results 32.20% Quakbot
2023-05-18Cyijot.jsjs 11ef57c233cd2baa14c4cfb9579839d381fbdec85d01923f9679f5ed21935f52n/a Quakbot
2023-05-18Dpzk.jsjs d4048bb4d8d517078d21db74a0238b8f0696dbad0bfb9cecbe0dad5e3a89bb47Virustotal results 30.51% Quakbot
2023-05-18Yfjjlxe.jsjs 8c2547beb9fb406c4a16f82f423ebe7c1ad3223e438fa0b061c7cc13133a635an/a Quakbot
2023-05-17Auzsjl.jsjs e05738fc1b53657500ed0ce0448f562aeb6e465927ca8d763f76dc97f3a2150dn/a 
2023-05-17Kdbnci.jsjs d2338cd0376171b31bef79e7bc05e3954d3c61c6f23184804a1a1110dafa3d36n/a 
2023-05-17Qhlzskwf.jsjs f95ae26c9bf7ecb6970afb88bfa12c71eafd8b35160d2c1658e57d36ea915477Virustotal results 29.31% Quakbot
2023-05-17Cpudssw.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-17Bfvweo.jsjs 905a894ac3b18458a8372c05faec1cd015ea3d7f3a5d248f87684a3062f2ca5fn/a Quakbot
2023-05-17Bifvpbjn.jsjs 9a8083ef127004e2a3fd6d38ac13339555b0e82a7347cc9a1aaa97c8dda4041bn/a Quakbot