URLhaus Database

You are currently viewing the URLhaus database entry for https://codixpharma.com/ml/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659175
URL: https://codixpharma.com/ml/
URL Status:Offline
Host: codixpharma.com
Date added:2023-06-13 15:04:18 UTC
Last online:2023-06-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: 0x48215333
Abuse complaint sent (?): Yes (2023-06-13 21:20:10 UTC to abuse{at}godaddy[dot]com)
Takedown time:10 hours, 13 minutes Good (down since 2023-06-14 07:33:43 UTC)
Tags:BB32 PDF Qakbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-14bobSuccDWQwXo.jsjs 7d62555b7556b1b9005b72497f471b0f4519e9d459cc69a9f3eea3ccb3df175cVirustotal results 0.00%
2023-06-14GhitF81q7YeWF.jsjs 2a1bbcde81a54fe5156996dc4b1413716e50c42e6ff7c2f02d5f3ca3c67ba4d2Virustotal results 0.00% Quakbot
2023-06-14edwpQBRQvmzhLp.jsjs 67a46e1abc05ae69934c409625634ad82d9964d9ab9fde45f3d44744b319d83bVirustotal results 11.54% Quakbot
2023-06-149EohyZ6SkFpMgg.jsjs fb2069ff3fee20a7d75c6ea45912c4e449c0969c3fa99cb9fcc2d7a8a30d8949Virustotal results 17.24% Quakbot
2023-06-131IrvvH7usMAT.jsjs 0844e94ba68d1390cfd3197f9bf9bdebe3c09041a2de26f8d3f5f5393c03e131n/a Quakbot
2023-06-137nbSOUWPm3M3C.jsjs 04e6eea889711e2622b0a0d711caacbd10814d4aa2dc52f1660b0b4dfca55161Virustotal results 15.25% Quakbot