URLhaus Database

You are currently viewing the URLhaus database entry for https://myrealmood.com/let/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635892
URL: https://myrealmood.com/let/?1
URL Status:Offline
Host: myrealmood.com
Date added:2023-05-17 13:06:52 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100117251 created on 2023-05-17 13:07:45 UTC)
Takedown time:2 days, 8 hours, 10 minutes Poor (down since 2023-05-19 21:18:39 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Ifyq.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 25.42% 
2023-05-19Zmvn.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-19Gkueh.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ddlt.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Dhjftn.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Aifmrw.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Dgctt.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Sxugu.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Zveouk.jsjs 26f944188fc1c8a3505238e1504dc074d39006e15f47e7ae2a2b4d719edc7e31n/a 
2023-05-18Jtmhcuj.jsjs f4fb9e206467712813d87a31c0ea3285bf1a5ad9658839ca77ac0a61dcbf0693n/a Quakbot
2023-05-18Gcnwwflj.jsjs f65cfd45df99f110dd5e24acdcb4a032a333c2d5f289d2867feb0d7fc6aa1960n/a Quakbot
2023-05-18Jhpfvu.jsjs 983c9fb0828b90c43eda528aaf767c2c7d4b71d59b86ad0d04461db11d91794bVirustotal results 30.51% 
2023-05-18Dswdskjh.jsjs 90d7044e2b3c6695b8ce4be887d9fedf198e2631c47d77093e427bbdc2ff19fdVirustotal results 29.82% Quakbot
2023-05-18Efntm.jsjs b77866fad79584d4eeba2fb19ac488731b788c0c7c1ca30001f91741db44e06en/a Quakbot
2023-05-18Izypn.jsjs 3302a636901e95a2eb9b66a8fdda7e3cf8997cec8749d879da126651b259557cVirustotal results 26.00% Quakbot
2023-05-18Okpzzuz.jsjs 5b081d8987954ca182f1f9c83eb5c24851ef6647e29f84c5fde150d826531e53Virustotal results 26.32% 
2023-05-18Pwbqhldg.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2Virustotal results 25.42% 
2023-05-18Kzckxxl.jsjs 1d57c903d9a9f7a6aafe34d3d44ced534b1878b64b93029c391c25c05c708094Virustotal results 24.14% Quakbot
2023-05-17Utfd.jsjs 98ca0fd1f80c8b41e2782376e1e44d8dbd142e3c6e7f91e3459aed684bf210a2Virustotal results 25.86% Quakbot
2023-05-17Vfglrhq.jsjs 50ea4195ce44fd0c177d6c8bca4b2a4f34676b3b8cbddaa734fe11cf5a265f01Virustotal results 24.14% Quakbot
2023-05-17Lrhwbz.jsjs 714d6297effa9020249e19940853d50dcb2ba31d5301a716f34ddf73f9a58bf1Virustotal results 28.81% Quakbot
2023-05-17Gfsksu.jsjs af020f4121ed33dba057c101c7d8fb714a2c96c883601c63acf7dc505818a5a6Virustotal results 27.12% Quakbot
2023-05-17Khfnyiyk.jsjs f7e8b96be3ac805e339ea8216ff018b90165280b8feba0fb873973b6f18ca747Virustotal results 27.45% Quakbot
2023-05-17Rkoposli.jsjs a581d1bc0926e4888a7d919a2ec529d51e03862bf784ac4cd4333e3df168d239n/a Quakbot