URLhaus Database

You are currently viewing the URLhaus database entry for https://peoplesfinancialfreedom.com/rb/?017761 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635950
URL: https://peoplesfinancialfreedom.com/rb/?017761
URL Status:Offline
Host: peoplesfinancialfreedom.com
Date added:2023-05-17 13:33:06 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: fabjer
Abuse complaint sent (?): Yes (2023-05-17 13:34:19 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 8 hours, 58 minutes Poor (down since 2023-05-18 22:32:40 UTC)
Tags:qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Fjgyq.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Cysifk.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Yoxis.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Anhfl.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Bikx.jsjs b499f7d9f3f301f1c742d78e70ca5d6c7f3311d85da230b809b9b2a02efe3662n/a 
2023-05-18Qsak.jsjs 78a09834bde88bcf04dd934a793540b810b090e90efb96a977c2477be294fc75n/a Quakbot
2023-05-18Vgfyx.jsjs f44e30ffb57afcf688c00896ca7384786ee3ede05210094b66c6d9d6c83675e9Virustotal results 18.52% Quakbot
2023-05-18Yjft.jsjs f80b9a7940830c735c2fbaf225da18389f25dc1ed7ef8e073311c9b3d680a95bn/a Quakbot
2023-05-18Itts.jsjs 6d9b8f4761b3d2b4e1c031cece4e6ae593e6a9e7de18a01dd28c1235bf7900d7n/a Quakbot
2023-05-18Tjvu.jsjs 1c70b83f5b4051ac542278897c3b02f334291507f01f685e95893c574241e6b2n/a Quakbot
2023-05-18Pwja.jsjs a1f08963f5715bb8830f2ea036c6be1f8a5f34bc8a6bc799c36611f79e54b14dn/a Quakbot
2023-05-18Utayey.jsjs 53182e2434b52d11490f911c908c6c23755d667fca1a03ac5d4be2cc9b0cd61dVirustotal results 23.73% Quakbot
2023-05-18Qccec.jsjs f2a2ace114103a041e79ed5165b96ac32d3595aaa0c8f1ff92533be7728179a4n/a 
2023-05-17Zlqnjliw.jsjs 3c4d813af231229cc2b961a17a923de449a9f8d67439dd976effea73360ff766n/a 
2023-05-17Ehzj.jsjs 5385fad188601d9e6dde0c124799956c0f227ef163e10a45533ba701150ef12fVirustotal results 11.76% Quakbot
2023-05-17Kxchle.jsjs 6bf7410f1b32c7fad44030961607fb13ec400a2a008f5817485ba84c5c297175Virustotal results 27.12% Quakbot
2023-05-17Xgsmaxm.jsjs 4de3c0071371884b0a2e8815554e19a2c0d89112e1bd9bc512d30aa306d3f0a9n/a Quakbot
2023-05-17Greqk.jsjs f74f3f66b468e91f7060adfeff51f084fd09fb44b5d93a66ce1b2cccdd016bdcn/a Quakbot