URLhaus Database

You are currently viewing the URLhaus database entry for https://uniquefragrances.com/ret/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2646444
URL: https://uniquefragrances.com/ret/?1
URL Status:Offline
Host: uniquefragrances.com
Date added:2023-05-30 16:50:56 UTC
Last online:2023-06-01 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-31 12:42:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 4 hours, 19 minutes Poor (down since 2023-06-01 21:11:21 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-01document_A048_Jun_1.zipzip 26d3e1d38991dd1299c967891e4c9b6a81fffc10bb56671b5f03576f248d07e4Virustotal results 22.58% Quakbot
2023-06-01document_B978_Jun_1.zipzip 363912a6be1d3e2d00ddebabac87635d05f52ce7ae2c202db4f1abb4399325d6Virustotal results 20.97% 
2023-06-01document_B134_Jun_1.zipzip 878f32544b8d01cf0266a37bba0c891b7a9faa49019b16cf08a9b09ac3e55fccVirustotal results 20.97% Quakbot
2023-06-01document_B926_Jun_1.zipzip 8f67f4edda0e813c4879714bcead146cd2b9cd15932f557dc372707b92599764Virustotal results 19.35% Quakbot
2023-06-01document_E156_Jun_1.zipzip ac027b8e5b8b2902a157f0dbc4d2417c95611e193468553a9e38e9e7d6616b5bn/a Quakbot
2023-06-01document_C195_Jun_1.zipzip 2da6dcd380acc5c380349f0908087dd45952f8f7fed9545bb480fc4589fa241cVirustotal results 20.97% Quakbot
2023-06-01document_B135_Jun_1.zipzip ba5e002b0afab586d4f443692c12c11a6def52cfc3ed7795c840db8d7d180277n/a Quakbot
2023-06-01doc_E367_May_31.zipzip b33fe3a11942f04fe76bf0a8e708e383011ad59f733f7086a4598626f5942318Virustotal results 17.74% Quakbot
2023-06-01doc_F186_May_31.zipzip 4cdd6aabd5b9f60d42e9e84fe7d3dedc3f8d8bdda4f6de97b1c7d46581d24219Virustotal results 19.67% 
2023-06-01doc_C217_May_31.zipzip ab26e38b78ff38d24651a580f28ad0d8c77d51c9abae81e56f2d6ec76fb78d62Virustotal results 19.35% 
2023-06-01doc_F039_May_31.zipzip ffb2bd15715724131949ad5e87c1d92716559f96fc8622127b6e5a38b07730f3Virustotal results 19.35% Quakbot
2023-06-01doc_A718_May_31.zipzip f5cc66789cf964c0ddc5be0d71581574880499995304884453c0a88c2b98d58dVirustotal results 19.35% Quakbot
2023-05-31doc_D780_May_31.zipzip 88083bdcb5f0067600e68951a227b16c51e00cad763d1b36fa6a0363fda3097dVirustotal results 17.74% Quakbot
2023-05-31doc_B780_May_31.zipzip 56dec9d2cc2a9f32482bc8006f8858fec204151b6de3b8603958e57c37a5fcd3Virustotal results 17.74% Quakbot
2023-05-31doc_B782_May_31.zipzip 6258e12aea6e5edb1594d2607b7cbc73ff4c0c8cea4f9c04301268c8b5535c36Virustotal results 20.97% Quakbot
2023-05-31doc_A546_May_31.zipzip d96e218870df535028886fa421421c8ee7e6c13744537cfe0e7254973bd45a41n/a Quakbot
2023-05-31doc_D579_May_31.zipzip 9036af9dd74a219e888a638563f25b30d5d8195126006931ef704e0a0d0dd46aVirustotal results 19.35% Quakbot
2023-05-31doc_D359_May_31.zipzip f8245463e29eef01b262c4da624d8db7f508fa839cec036cf84007f7f992edaeVirustotal results 20.97% Quakbot
2023-05-31doc_C061_May_31.zipzip f50e8d37a5d5ad52d36b211a197c8d83f9c8b16d41b2cfeb49fb0ee367c81346Virustotal results 24.19% Quakbot
2023-05-31doc_C431_May_31.zipzip a0dc5ad9bcd6f3c1a0fc74343d69bec979c1870cd79f6a3bf75381ccff48c997n/a Quakbot
2023-05-31doc_B981_May_30.zipzip 0ca25d0b8cbad55a58652d95ca658d4d4ee4dcd285e17dd498ff53492b0e1513Virustotal results 20.00% Quakbot
2023-05-31doc_F853_May_30.zipzip 42586d5c879cf52aff95799b6cb7631ceedb76e479884ed339764c8ae0ffaf81Virustotal results 20.00% Quakbot
2023-05-31doc_D240_May_30.zipzip d0b56a2cbdfedfc16593fcf26d007632e9ed50219cac97c3766645f87d74d382Virustotal results 20.00% Quakbot
2023-05-31doc_A539_May_30.zipzip 68a50e021eb205c71e72fe1e19a0300f124627872f0b234af9b0118c3f2c8435Virustotal results 19.35% Quakbot
2023-05-31doc_B315_May_30.zipzip 64177c29c8db46e61dd1342f396f4cf8cbfbe4e47129f77f1051f0957f837f13Virustotal results 20.97% Quakbot
2023-05-31doc_E124_May_30.zipzip ce59f8e6a914dd972f6809624e4a21aed1ed04b31b01a1493020c8785357f085Virustotal results 19.67% Quakbot
2023-05-31doc_A492_May_30.zipzip 5687f0fae2a937ee9ac6bb2601ff1558b50b4785ec36849bf99bad96c0109c4bVirustotal results 17.74% Quakbot
2023-05-30doc_C805_May_30.zipzip 4f75dfd421785423fd352fee5332ec84e265d102ba14dca8d05273b046ce883eVirustotal results 19.35% Quakbot
2023-05-30doc_B836_May_30.zipzip 94512a5cc912a842ccd99bb914712c8f200a67384544cb68fbf25672652df0e1Virustotal results 19.35% Quakbot
2023-05-30doc_C285_May_30.zipzip 4fc73d7af6bef7fdaa836310dba5cace4d2164b247e5585f72760751bebd34ddVirustotal results 20.00% Quakbot
2023-05-30doc_E785_May_30.zipzip 03454b2938c634094cc0d3d44704d499ba300f925581b4207c024b8563510fc2n/a Quakbot