URLhaus Database

You are currently viewing the URLhaus database entry for https://safes-endocrine.com/ia/?476352 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635960
URL: https://safes-endocrine.com/ia/?476352
URL Status:Offline
Host: safes-endocrine.com
Date added:2023-05-17 13:33:08 UTC
Last online:2023-05-18 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: fabjer
Abuse complaint sent (?): Yes (2023-05-17 13:34:28 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:18 hours, 44 minutes Good (down since 2023-05-18 08:19:25 UTC)
Tags:qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Fddjsek.jsjs 1d6e41a96832fff256d4c07d7cdb318a251230e1445351f5ad36b87ce958bf1dVirustotal results 25.42% Quakbot
2023-05-18Cirv.jsjs d4048bb4d8d517078d21db74a0238b8f0696dbad0bfb9cecbe0dad5e3a89bb47Virustotal results 30.51% Quakbot
2023-05-18Vxmrafk.jsjs 81c46b64d5ec7559ae3287d14b77e2574baf7808d818c8b6f2375da96a544c50Virustotal results 27.12% 
2023-05-18Mfpy.jsjs 5cc7756639a24d5a8e14f7884507a76c1eb16843689035a0792202694705accan/a Quakbot
2023-05-18Zmvxkxb.jsjs 38994d258f8bfb97fcb4ad671d962c6f000efb90f29ef01a8ca9881d7a206c66Virustotal results 27.12% Quakbot
2023-05-17Xeuj.jsjs 397ed6d5f113de3b5a638878e1ab22bb58f5fb493aaef92441db571bcb4c81b5n/a 
2023-05-17Tauj.jsjs 2c402bf5ac40a8110c89bcf0f4ccd617ba22f8e8a6ca32d9949461c82540e48aVirustotal results 28.81% Quakbot
2023-05-17Tswvdnmy.jsjs 26a9ccdd2cb5bd68aea8b06532a4945f8f6585f5ee8e03fd64c7dd7ba9bde535Virustotal results 25.86% Quakbot
2023-05-17Qelqm.jsjs 29d88d7a73d988b2b2c5ddc76ac150742366a2a8c379758bf47f13c2fcf01346Virustotal results 27.12% Quakbot
2023-05-17Lecm.jsjs b89d6433da85e8b53b60dd8f31aa096c923d9b4fb337c03d3b381482ef280974n/a Quakbot
2023-05-17Rcsxp.jsjs 2e6fa76c0870d4318d71a8defd95759f831cb88397931327f00478d853bc9525n/a Quakbot