URLhaus Database

You are currently viewing the URLhaus database entry for https://mybabezacademy.com/vtuo/?409871 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635952
URL: https://mybabezacademy.com/vtuo/?409871
URL Status:Offline
Host: mybabezacademy.com
Date added:2023-05-17 13:33:06 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: fabjer
Abuse complaint sent (?): Yes (2023-05-18 17:40:11 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 7 hours, 31 minutes Poor (down since 2023-05-18 21:05:25 UTC)
Tags:qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ivulcf.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Isti.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Rbxvpgfj.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Mcvwbrgt.jsjs 509870da27879560bfb32380332a1cb3a8f8a17deed5003e959b8e4fb1be4f86n/a 
2023-05-18Pfltw.jsjs f16b3c48ca1ba324e53c48a72c3bc53329423b16779e1cd1d0d40447f39cfefaVirustotal results 16.95% Quakbot
2023-05-18Zpxr.jsjs 320db1d64ed5a7a4ed401ebf9861a9776e220be46c59f4113bebf562f9e506f3n/a 
2023-05-18Iokxlkcp.jsjs aaa4050b504cc828d80b7057106a778bca86d9e00c674992ba5ee3eddf1db803n/a Quakbot
2023-05-18Trwip.jsjs 7a4ab56c0029ea06eceabbc4e8b9f005b37b97d1ea376ed3db95729269780e17n/a Quakbot
2023-05-18Shtxqyd.jsjs cac584e2ff62f01ca51db682d0b6d32ff11123c3bc3b6a5e9794606ad51844fcn/a Quakbot
2023-05-18Uzgwh.jsjs dd72eab3dc3f67fee1ec6cae276e3ecb4fd364daf45f773c22f8a0c771fbf742Virustotal results 25.86% Quakbot
2023-05-18Fqjevq.jsjs a0220d487566d1243b11c30ea5d37349418d84e8f6eb6013e0792aa4b11236c6n/a Quakbot
2023-05-18Xeki.jsjs 59eafea575993fa2b9b1a5a60ec2852f5cbda6491cc6c163e79d91e7fc9b1d7eVirustotal results 30.51% Quakbot
2023-05-17Rqjqlsaq.jsjs 2c6c3f6ffb898b9a29cc0a5ec84ccecf30800496946b378d5558f81798278c3aVirustotal results 32.20% Quakbot
2023-05-17Javsv.jsjs 170ceff8d051e5addeb6beb1128383fe814b7b40738b54c0f99409de5ccba2c6Virustotal results 25.42% 
2023-05-17Gqviqf.jsjs 8cb9812b4c0409176b2f0770497520692218130496cf0a2a363b4606ce28f506n/a Quakbot
2023-05-17Xbzibpk.jsjs f3cf1988e5b288b64fc34cf15045d67a4fcd2c9c61549510e3df907ea1f61cf8n/a Quakbot
2023-05-17Gmqax.jsjs b88c04bb3bdf213453514ee3d92c8a7fd5f5e014017ea615f8df49c9c0a7ebefn/a 
2023-05-17Cjlba.jsjs 3e80a8823bae07e1aca749a62a6da2c57f0f80ebb6d4a8cd1be2ea749d3af45cVirustotal results 13.79% Quakbot