URLhaus Database

You are currently viewing the URLhaus database entry for https://elsassdestination.fr/sd/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645622
URL: https://elsassdestination.fr/sd/?1
URL Status:Offline
Host: elsassdestination.fr
Date added:2023-05-30 12:09:11 UTC
Last online:2023-05-31 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-31 17:06:08 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 10 hours, 2 minutes Poor (down since 2023-05-31 22:13:27 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_A102_May_31.zipzip 0c97f415ab9452167e4fb92172598923ad8645bc1b430209e4dcba5df226dfc7Virustotal results 17.74% Quakbot
2023-05-31doc_B871_May_31.zipzip 12bffc86d71d3cae1bb082a8df1709dd8fb0005137feb822434ce0931eab79b6Virustotal results 16.39% Quakbot
2023-05-31doc_C641_May_31.zipzip fc8b0c70ba35028d2fd098ec756779ca97f4d97bed98cb223fb3446fb0ac6955n/a Quakbot
2023-05-31doc_A856_May_31.zipzip 9653b4243c05e1e8e748bb5e1bdf9832667ab6f7e80d04d039492f025505e62aVirustotal results 24.19% Quakbot
2023-05-31doc_F037_May_31.zipzip 08de76724cc9bccd23b997310c6bb1ca96bf08be396bff93690db4f8247974c0n/a 
2023-05-31doc_C943_May_30.zipzip 5720c340128ef434f12b46ee89701019621bfe86a3baeb42c61f54ee29b6c96bVirustotal results 17.74% Quakbot
2023-05-31doc_D563_May_30.zipzip 71a849e80d10b21dec3b6d38d47961dd45ed4dead581da93ce71f179332b3d3dVirustotal results 19.35% Quakbot
2023-05-31doc_D803_May_30.zipzip 5173749e378704f14c106cf3ca74e882fec8d71134ca97524c70e4c0fc1d4c45Virustotal results 19.35% Quakbot
2023-05-31doc_E784_May_30.zipzip 284bc44fbb7ca4a5addb4f123e7d98bdf108ee2f6e1f7d52739a1dc7814a3a1fVirustotal results 18.37% Quakbot
2023-05-31doc_B935_May_30.zipzip d230b08f9ec44098a135380bcabfa34d070f0428195b7224798219cf63b27f54Virustotal results 19.67% Quakbot
2023-05-31doc_E015_May_30.zipzip 2a4f181b713c9f2bce4cdaa11a59213dd443387122971828493c78527bc01531Virustotal results 19.35% Quakbot
2023-05-31doc_A693_May_30.zipzip c3333833e279f23696314f06a9fb08229b2f010ed379c8ce8d14d07742e28cc4Virustotal results 19.35% Quakbot
2023-05-30doc_A270_May_30.zipzip 226e4d0e13a091fa6daef0d3e516034116381b03e0cb8ec1ab162144f0133c85Virustotal results 19.35% Quakbot
2023-05-30doc_E516_May_30.zipzip 9317a62057e6f62b4a865d856456a2262de0af4e9512205a4f1d078ec948d183Virustotal results 18.64% Quakbot
2023-05-30doc_B863_May_30.zipzip 01796538a7a73564c055d57e6189735bff98ca1b5802e1a9658e62bce27e20b8n/a Quakbot
2023-05-30doc_D830_May_30.zipzip 402f57a2ef98b74a6465463cf24835cfa2cbc2924f233016d4e8de427fbc1672Virustotal results 19.67% Quakbot
2023-05-30doc_E026_May_30.zipzip 4e2f7b7a49357bcbef923c472c10934f2dac4dc46a6740378f3ebc1bf474e871n/a Quakbot
2023-05-30doc_F096_May_30.zipzip 3eedc5fd3a1156c0c25cc0657a5055cf4359cba1f2b52af2d9a90244c2dcaf9fn/a Quakbot
2023-05-30Cancellation 395137 May 30.jsjs 31d9b9c8b52f0881ae06befa926ed4ef4578ee7475c191b61f62c04f21de8c82n/a Quakbot
2023-05-30doc_F364_May_30.zipzip a2d14451bb4f40a85937315f60ea4ac783281f2f7d66f9a83ef1e7d84f14c610n/a Quakbot