URLhaus Database

You are currently viewing the URLhaus database entry for https://thiscss.com/eamv/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635873
URL: https://thiscss.com/eamv/?1
URL Status:Offline
Host: thiscss.com
Date added:2023-05-17 13:06:50 UTC
Last online:2023-05-18 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:45 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:19 hours, 6 minutes Good (down since 2023-05-18 08:15:48 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Fsdmrr.jsjs c5cd6ca0ca7e79a3c24d0b2e608780ee8eff700153663539c8be58f273a24565n/a Quakbot
2023-05-18Gfezyh.jsjs 50181b4f3b73fded444a5822e9aae57537b05f693c1a1887d0f8b54f0f597de3Virustotal results 24.14% Quakbot
2023-05-18Peczbj.jsjs 73abfbef5c169e5239c78d4c04f3d18f7f72490c2ca0cbbb33d92cac9675dd16Virustotal results 27.12%Quakbot
2023-05-18Mxwcn.jsjs 3f883b067422272c3b10eea88505351741b599d103f66676cb75912106735cfdn/a 
2023-05-17Jcct.jsjs d3c173c2dfa25e646847bc107890d76906c807bf85968b5dd9e96044a7729b2fn/a Quakbot
2023-05-17Uhnupnwc.jsjs b8080e6708e687876e70fb9577bdb538b92f84133aae0cd311c456094c77efb9Virustotal results 25.86% Quakbot
2023-05-17Guudhgo.jsjs 023250d4f9af49d2f7968647280c712aff55b6146a5a06b7b302bab288a405baVirustotal results 29.31% Quakbot
2023-05-17Jthfqsq.jsjs 76b1f9267eb932c85c8717778e7399af2196f31c3f1ee4b76d83a2cc5f2e486cVirustotal results 25.42% Quakbot
2023-05-17Vqckpulx.jsjs 3c55d89d269d20d6852bd0da433091d1fb247c736acddefdf23c414213857e73Virustotal results 31.03% Quakbot
2023-05-17Fzbiqj.jsjs a64cebdd853596ce95beeb112b9dfab6eab26ff09b77eaad1c909cb1b6cff48an/a Quakbot
2023-05-17Jqgz.jsjs 79b1f8ec256643dd38b44883fae1a1c46e851db6d07560d38f8cb371756b1fa1n/a Quakbot