URLhaus Database

You are currently viewing the URLhaus database entry for https://fmalegal.com/iat/?165252 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635961
URL: https://fmalegal.com/iat/?165252
URL Status:Offline
Host: fmalegal.com
Date added:2023-05-17 13:33:08 UTC
Last online:2023-05-19 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: fabjer
Abuse complaint sent (?): Yes (2023-05-17 13:34:29 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 8 hours, 35 minutes Poor (down since 2023-05-19 22:10:17 UTC)
Tags:qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Ijgyvjsi.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 25.42% 
2023-05-19Abjmirbk.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Ljumltvo.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Jxplluu.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Nfiph.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Zomvewf.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Lbwkpgle.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Sagafdno.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Eyjrlq.jsjs 41e69b4a6ae947bb27d0dc9d43b718982363bd06c774dcc72a81db274a5f9095n/a 
2023-05-18Vekjyd.jsjs f093b882b8fd4a20a6b626c96af959ed31285d4cd57354e4cf7de124fb062b81Virustotal results 30.51% Quakbot
2023-05-18Lzuabiby.jsjs 59eafea575993fa2b9b1a5a60ec2852f5cbda6491cc6c163e79d91e7fc9b1d7eVirustotal results 30.51% Quakbot
2023-05-18Ofmmkj.jsjs ba7f993248a05baa4fc8af51ce3e8f89889e817065c4b964cb37bfc088ae75d1n/a Quakbot
2023-05-18Yjhhquee.jsjs 66718c6f0ac9419d7f5bb30cef5272328e503b226e7ee6157072e26782f6421fVirustotal results 16.67% Quakbot
2023-05-18Ypane.jsjs e50fb972f8f78042286895b6d869daf014f5e8082e3c3989ca853daee780a6aan/a Quakbot
2023-05-18Bfanlm.jsjs 62f72a40ec519cd843b1c38ebe9ee2be23628961bffc952c1da59c3687a87466Virustotal results 24.14% Quakbot
2023-05-18Ksgo.jsjs 19c40585627ffe423ed5f0a6da7706a51a4e068323d3f9cd2f54a01d45c02af1n/a Quakbot
2023-05-18Kwwlvzhc.jsjs 0857b5e40844024689620ed0e9d9fbef8b9b295f54e11fba7dd9693f59ce40fdVirustotal results 27.12% Quakbot
2023-05-17Mkyh.jsjs 714d6297effa9020249e19940853d50dcb2ba31d5301a716f34ddf73f9a58bf1Virustotal results 28.81% Quakbot
2023-05-17Xiwvz.jsjs 6341f87ee4bc63114ac2e7899107fa341aafda80e5fa00f00b0f72d89ddc06d9n/a Quakbot
2023-05-17Wgkx.jsjs b9db0988cfc1418354e6e55c54e7346c335a55a40661a6907d35143a9f8f8f8cn/a Quakbot
2023-05-17Hyjbl.jsjs 27d3fa3ffa307f97bc3047f15898d338734929484e224f43ab8740c710601a78n/a Quakbot
2023-05-17Yuzvaga.jsjs 1f4c2a4e8c95bab7ff916109a3978612cf0969f85e9f00ded884776dda11eefbn/a 
2023-05-17Khjz.jsjs e7b23f3002dffd67a5026b9ae031fe92c033bd7c37c6bb15323d3bb075275d89n/a