URLhaus Database

You are currently viewing the URLhaus database entry for https://reflexmall.com/uala/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2647846
URL: https://reflexmall.com/uala/
URL Status:Offline
Host: reflexmall.com
Date added:2023-05-31 14:29:13 UTC
Last online:2023-06-01 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-31 14:31:00 UTC to abuse{at}hetzner[dot]com)
Takedown time:10 hours, 13 minutes Good (down since 2023-06-01 00:44:50 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_B846_May_31.zipzip 7bef4296abc4e31dab9382bd364198a39dda6e1840fda0d056fff7c9a3ea9d32Virustotal results 19.35% Quakbot
2023-05-31doc_E163_May_31.zipzip 84eb5b4ddc4dd8c70b499a0305f147ff69c0a573f6926c16f1fdc3fded14482cVirustotal results 19.35% Quakbot
2023-05-31doc_B602_May_31.zipzip c781a7547411ef33f2601664972a7be2973f338bc514c6e5a2df0e2de94839efVirustotal results 19.35% Quakbot
2023-05-31doc_C591_May_31.zipzip 30fd7cdc0a6462152ba2339bab72e8c87ebed26836f03b30be77102fcd758e4an/a Quakbot
2023-05-31doc_E971_May_31.zipzip 7718a3ebbbfca88fd6ffd2e862d2a082f075ccc6b539f40b0787a09e160278dfVirustotal results 24.19% Quakbot
2023-05-31doc_D435_May_31.zipzip 14ed5a71a472026ddabf1d45a08c77058d0b53af5bd48b422983e8f1d6c9c869Virustotal results 24.19% Quakbot