URLhaus Database

You are currently viewing the URLhaus database entry for https://xpertssol.com/cios/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2638918
URL: https://xpertssol.com/cios/?1
URL Status:Offline
Host: xpertssol.com
Date added:2023-05-22 15:02:13 UTC
Last online:2023-05-23 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-22 15:03:22 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 0 hours, 18 minutes Poor (down since 2023-05-23 15:21:40 UTC)
Tags:geofenced js Pikabot Qakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-23ReabandonedViselike.jsjs aaeb10dec1993cb32cb58db63d498d308559b58d0e0591f2a962d7e9f95191ebn/a 
2023-05-23Zlzxfphh.jsjs f61b9be3569b12caa349435dd80ca4b48b2096537af3978d2d32e94a9ba2f145n/a 
2023-05-23Iulecjk.jsjs e615b9b18ee1cdbc8155cdcb73cf0fbeff64286b019e8fefbe862ca5b3809e30n/a 
2023-05-23Klstbk.jsjs aecf27138c531bb928a8251a4e45440865a57191d67e68c7e72b30d8bca138d6n/a 
2023-05-23Lloengzi.jsjs c0e2c57a2c2b9ea7318a52575951836786549e93fd6124f3a6727f1443e16455n/a 
2023-05-23Qdxgw.jsjs dab8c58d6d93df55d3518a2be895a9b5041df07cff855146747a852dd9de6da7n/a 
2023-05-23Tjzka.jsjs 5416e3992cc710316d4f9e6ae7781fc66744d10f3074490982e8e5891de912e7n/a 
2023-05-22Psyu.jsjs 47160f4abd4d0f3bcc2008781f1b837e88cdc46e60a6e53ce53fc6bebae5f2b2n/a 
2023-05-22Orytpbeo.jsjs f5fcefa9fe94c755fa282cf98ab680446a93f820f2f79115f66133b6f2f44d6dn/a 
2023-05-22Tfapsh.jsjs 96a3bd29b4434c521979f5d03646c37e4c58cab77e231ae0e58202a4a578f77dn/a 
2023-05-22Afopa.jsjs 143e23d30ca40ba7d2b03076837924aa7ccf1977bae19c809b86349dd3d54a0en/a