URLhaus Database

You are currently viewing the URLhaus database entry for https://fitochem.com/spn/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2639044
URL: https://fitochem.com/spn/?1
URL Status:Offline
Host: fitochem.com
Date added:2023-05-22 19:54:07 UTC
Last online:2023-05-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-22 20:59:09 UTC to abuse{at}bluehost[dot]com)
Takedown time:16 hours, 38 minutes Good (down since 2023-05-23 13:37:09 UTC)
Tags:geofenced js Pikabot Qakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-23Kmpxtc.jsjs b78b9fd989b7106ba1399bec1b0f56df1f6e4c98c189603dde120f2ece40457en/a 
2023-05-23Zybvnbv.jsjs 3fca61d2ef97838f1fca1592637213fd971c32bd110b8940d54e6466c622554cn/a 
2023-05-23Akndwmse.jsjs a97d9bebdf3e83d281b6dc8ac1f1516b0c3d30e23b587905961db538c41356f9n/a 
2023-05-23Uqrjl.jsjs 906ee89d745963ab376ff7e1a8430b0f4e81b15fdb8a2f06125242b3f463c41cn/a 
2023-05-23Ucnucwa.jsjs 17fadca350940afb92e7365f1fcfb3738331ca5e5b26d09486c35e5306200384n/a 
2023-05-23Aroqidk.jsjs 9426d56290f6cfa09f0962e0eb6699f2f3a290594a8dac7610f22de091388310n/a 
2023-05-23Wyphbhqs.jsjs e63b08be0c0dd710af8dba82661add9535503f635765d24ff10ed5a4bf30b013n/a 
2023-05-23Wspybwfq.jsjs dccc50685aa8c5952a1c432a9d2cdb416026df4f64a304c701e26cdc9d88f6b8n/a 
2023-05-22Rvxptd.jsjs 0eda15752caade6ffa66e45bc5e72b7f45188af8495d15c25ec92baa7be8d82en/a 
2023-05-22Qdpvaeel.jsjs 920179ff099ed95a1d8df9d38d6bd0bf16322675a5958f9a324b8d2deffdaff9n/a