URLhaus Database

You are currently viewing the URLhaus database entry for https://forslag.net/cs/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635889
URL: https://forslag.net/cs/?1
URL Status:Offline
Host: forslag.net
Date added:2023-05-17 13:06:52 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:12:06 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 8 hours, 37 minutes Poor (down since 2023-05-19 21:49:28 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Gthrmt.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-19Sjodndu.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Zhfakejp.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Ymqkje.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Asjxi.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Juwgmx.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Tkvnn.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Prqe.jsjs c4b212c5e7fd359120250be32309616edbc526ddeb31dfcf617cc54cf7f9305cn/a 
2023-05-18Uuevyh.jsjs 12551eef6e57f08df39d1185caa198cce871f9b27d1fb58cd74228fc3a949b99Virustotal results 30.51% Quakbot
2023-05-18Fvsgz.jsjs 89ddd75a9d671f30070d8ed74468e507a72e5ca5699855296beb959dae2b71b3Virustotal results 11.86% Quakbot
2023-05-18Cgunrhg.jsjs 39ac88782d43b40c56cd7245203211f747e986908f13072c8d6d6caede0ef79eVirustotal results 30.51% 
2023-05-18Pbpfwoav.jsjs 534fb18b08176440d03086ec406d8a79bdfaf1488c044a8355d161fd7e521950Virustotal results 25.42% Quakbot
2023-05-18Mbdd.jsjs 7237114103b60a76ef6a67916d0d6fc1e14dc707087bd27684d1093748393f39n/a Quakbot
2023-05-18Eayjtbuy.jsjs 3f3578034596c52f8ed357e2c3f37660c2f5af439da7fde722d26c629f457d03n/a Quakbot
2023-05-18Pwllqs.jsjs 784d0c23a7299fe8f5a79ce4f83765cd48535cf1afc25d542a0f854f8049d149Virustotal results 27.12% 
2023-05-18Wcbvqp.jsjs 75aba79d300dca2a11da16879bf5c0fd15d388a5926381550db24144937b72fan/a Quakbot
2023-05-17Rioez.jsjs 60483947f59c4a843833ac5302fae111fb318dafe639770153154f7e01c2afa9n/a 
2023-05-17Lehrtf.jsjs 0836ece78eb77f4b5ebf101fc5e4317ad5554305bff6466db565f247b93b5928n/a Quakbot
2023-05-17Ouwuj.jsjs ad227c276250c72ebaf4c13e5d960347009d0762b8c2e696a35b36232e0eeff0Virustotal results 27.12% Quakbot
2023-05-17Rkny.jsjs d5e6e30f18f2d0670de3202c27c125583667cb6be60aee992f59e72d23eed864Virustotal results 30.51% Quakbot
2023-05-17Zusqfw.jsjs b11ddd3e32db780631dee2546f8eb8498cf1976976b4f9b6229279881aff3e12n/a Quakbot
2023-05-17Cayoyhy.jsjs a5540977a0c0c5a143b8a2c6f71919f2181988f29747374bd66cbcebd4eb7b11n/a Quakbot
2023-05-17Mbkzm.jsjs 7f5bfd748f09cddad1977aabe48a77b4aa3281b4bc9ac685ca0e53226b92c107n/a Quakbot