URLhaus Database

You are currently viewing the URLhaus database entry for https://hepm.co.uk/oele/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635835
URL: https://hepm.co.uk/oele/?1
URL Status:Offline
Host: hepm.co.uk
Date added:2023-05-17 13:06:43 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:11:25 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 8 hours, 11 minutes Poor (down since 2023-05-19 21:22:31 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Pnbva.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 25.42% 
2023-05-19Hcrcta.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-19Urmfv.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-19Byqgobix.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-19Lvzcw.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Cnsz.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Sqjjsih.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Ljuaxhcb.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Hzcb.jsjs 30ba7da103635909d887d93104a058628a698569619a5ad2dafbd028431503d4n/a 
2023-05-18Ogjun.jsjs 6da4a8bacb02c6d1b3251c5978545168c0712fb14b5ec2731a867b73a3daeacan/a Quakbot
2023-05-18Jpvfucb.jsjs 8c4f0c45a34f4cd509c3354346e0db29fbbe4bd099e2b67de6abc88dde35081aVirustotal results 25.00% 
2023-05-18Agmlrvmk.jsjs bbea073ee85951ed23e95e826bbf93fe5f1cd1885d0b88476ba2cd5a1e6bcedcn/a Quakbot
2023-05-18Srqtiy.jsjs f11d7ad43d7a6c6cc716d06a9d41c96156d6ce0dc45d6add8d3039cae526e350Virustotal results 25.86% 
2023-05-18Wgfrokbv.jsjs d72be2d3e9fcadaa237d2573ff95eacd51e973b70514465c8d57e7cd957769b2n/a Quakbot
2023-05-18Oheigko.jsjs f39cee789a4050e31f3f61e2dae48c0b5328d480424a439ba3c06fdf7d12ba43Virustotal results 29.31% 
2023-05-18Jixdwmq.jsjs 9aa3958dd376fcd792957165b53999bc05bdb411a0ea61e30b7787e1a7cdfbf0n/a Quakbot
2023-05-18Izppv.jsjs 3fe82998dbbd1b56d6f2bf670fec8d276ac794d97facd50002a2cae0c1f41b02n/a Quakbot
2023-05-17Eowvsb.jsjs 37f6c3ef6d545c8b3db46550b00329b03390e7d7abfa74c5b03bc0c85f07af15Virustotal results 28.81% 
2023-05-17Zobbhou.jsjs 50ebb94dd22b6d976b5ec46e2aaa6756dd807058f1a4fe1497d72c4a355b3c2dVirustotal results 25.42% 
2023-05-17Bohtnbme.jsjs 0769e73bc4ebc2ee5fdfb2e6d02b6a282085b48c709104d96e856380e8e4ecfdn/a Quakbot
2023-05-17Fpdakdi.jsjs a2fee1f921c59d61590ed86bdd9e19a12b68d9722d228d0e5bef678bd31d461bVirustotal results 30.36% Quakbot
2023-05-17Jfeytwlw.jsjs 1bff54d9504766a1b23df7d6c83ffbf3db9ac0d0cc9ded739c34a0f1114f5717n/a Quakbot
2023-05-17Hrqllyq.jsjs cb852f121e9dc83aa982abacf01603aed7cf0dfd1ac5c52956539b688ad41539n/a 
2023-05-17Ooyx.jsjs dc776fb044bb27e20a16f383ecdaa44a67be283f4902ddd48f1f6cffd24d036cn/a Quakbot