URLhaus Database

You are currently viewing the URLhaus database entry for https://pfixs.com/rtsc/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635823
URL: https://pfixs.com/rtsc/?1
URL Status:Offline
Host: pfixs.com
Date added:2023-05-17 13:06:40 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100117239 created on 2023-05-17 13:07:33 UTC)
Takedown time:2 days, 7 hours, 59 minutes Poor (down since 2023-05-19 21:07:11 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Gldoi.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-19Orvmshim.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-19Knwe.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-19Lpcowg.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Vsyozozy.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Zwuffm.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Qlonqwnd.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Lxygbv.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ylke.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fn/a 
2023-05-18Hrus.jsjs 0efda647b9e6537d80702573e14dad4cae7edd5bb92d94eea0f136b93fdc03b7n/a Quakbot
2023-05-18Wbabpua.jsjs 5002cf2a22a794f451347414eae921d359f14704e2fc3491ec70ae29266a6ea6Virustotal results 22.03% Quakbot
2023-05-18Asuxa.jsjs 8319c01bce9a24d28eeb4e926938d179f37c880ab2aaa26290056ff5089ceae2Virustotal results 27.12% Quakbot
2023-05-18Uwev.jsjs 2072042cbdf8458366261756217da566a1b8d6cf4b24541a37d71c44c07c7fdeVirustotal results 24.14% Quakbot
2023-05-18Ehimadb.jsjs 64dff88a0434f88beb3fac1ad7fb2945b374f90e6ee2ee7322665681b945e790Virustotal results 30.51% Quakbot
2023-05-18Xean.jsjs 285384a5ccf94492475a9af926ddb24dc621f5b0f19df79f8ed7366ca130d544n/a Quakbot
2023-05-18Osbn.jsjs 2b2ddaf766a72a62c3247e520317d64f6b32231d8802b99b861cdbcd872a7ef0Virustotal results 27.12% Quakbot
2023-05-18Bgrxl.jsjs 07d1842292aa2619ebfbb551eff5580fb24f945283f3de4298dc06f9493b6b20n/a 
2023-05-18Ynoghler.jsjs 9b45c4614db7627fee14ec88aef1faf7e97115a9755ad170998bf331df8c2b0dVirustotal results 27.12% Quakbot
2023-05-17Mlas.jsjs dc0d873178c61dae13dac14d65611d4716e9c28ebfa216e32126dbdd1ac971ben/a Quakbot
2023-05-17Rcxysr.jsjs 003a7f907bd61ac3b7c2a9dddb1bcf8822364010b01853af755fca54c3f2fd80n/a Quakbot
2023-05-17Nhizvrlv.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2n/a 
2023-05-17Habzju.jsjs 3b367e99561731587beb5622ae151a88c15c2153723768a743a9b7f635cf1303Virustotal results 30.51% Quakbot
2023-05-17Sxgpy.jsjs 4de3c0071371884b0a2e8815554e19a2c0d89112e1bd9bc512d30aa306d3f0a9n/a Quakbot