URLhaus Database

You are currently viewing the URLhaus database entry for https://alrabehpack.com/tu/?225252 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635944
URL: https://alrabehpack.com/tu/?225252
URL Status:Offline
Host: alrabehpack.com
Date added:2023-05-17 13:33:05 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: fabjer
Abuse complaint sent (?): Yes (2023-05-17 13:34:13 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 8 hours, 11 minutes Poor (down since 2023-05-19 21:45:57 UTC)
Tags:qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Jzhnjoss.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 25.42% 
2023-05-19Ajzdagmu.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-19Vxuw.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Ssbm.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Qwdrc.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Pfchtb.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Qvmne.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Spdsnhx.jsjs bee57b7824b8d43163902a05bb3870577b0c78b3af4b9fa5fedb4aac3435dae2n/a 
2023-05-18Flztm.jsjs 6ee195c06baf35069572750e08cf581ee2a7a59c0b75faff8c5284a839f34ee6Virustotal results 32.20% 
2023-05-18Wwcibaa.jsjs a1f08963f5715bb8830f2ea036c6be1f8a5f34bc8a6bc799c36611f79e54b14dn/a Quakbot
2023-05-18Hwyos.jsjs 831bcd763103748a036135443a32ea80a8d0c311ba22872149bffc13eec6efc9Virustotal results 30.51% Quakbot
2023-05-18Rmogpp.jsjs 34d43862c3788ec764c7fb735ddcfc1f1712a66632a3bf7e8b83cadc98a6faacn/a Quakbot
2023-05-18Yhpae.jsjs 57924347ed17b5b79fa35f9c3f130733079566dd527de61c8d1691c0e4f0a7f2Virustotal results 27.12% Quakbot
2023-05-18Gntiusv.jsjs 5526b208f51ee2b6adbf6b588401d5c1e058973988c16897fef27cdf25f2a51an/a Quakbot
2023-05-18Sovkcilv.jsjs a569ce1eb1902d2edf7cffba78e832e764170e48ecfe81ac3adda07c5f42455eVirustotal results 30.51% Quakbot
2023-05-18Bjnunr.jsjs 6e98b0ad9b6fe81e7dde4a5e76cddfdc25b19695ca702e4faf95f45dfc5a65e4n/a 
2023-05-17Styq.jsjs ec6f55b9c56d3dead8b8490dfbbcccadcdfef62b7d67c671b8d0ee9620f4b74fVirustotal results 16.95% 
2023-05-17Hbrtekps.jsjs e84b4920d25503f9505dfe8813b964551aa485cc176eb30dc5ac5e46dd5d56bbn/a Quakbot
2023-05-17Aenqsii.jsjs 72c9727d22512473f4aa27d93e0c15ae33a95784d9804b057275d0d7d8b0a361Virustotal results 8.62% Quakbot
2023-05-17Uciorvbg.jsjs 81d46bf6cc71d927906bc2a9ae29103ed6a1d3f01599e9736dd016267c874521Virustotal results 11.86% Quakbot
2023-05-17Grxemd.jsjs deeae69c4717d775bf5fa189632028d3bea8fff66b068f15bb1c163430d3fb84n/a 
2023-05-17Oxzjey.jsjs 8045c5474873d54e74acd15fa59448b63e4a6d443562ce14223f30374924a094n/a