URLhaus Database

You are currently viewing the URLhaus database entry for https://khidmatic.com/tpd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659241
URL: https://khidmatic.com/tpd/
URL Status:Offline
Host: khidmatic.com
Date added:2023-06-13 16:33:16 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 16:34:12 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 58 minutes Poor (down since 2023-06-15 17:32:46 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CF785_Jun_15.zipzip 4cd2281ad71d07d96f8f91d7c3b9c18ba6b7cea23baa3f0ccea528c57509af0bVirustotal results 6.45% Quakbot
2023-06-15document_BE538_Jun_15.zipzip 4dcbfe077f2eb88940eb3c3eae6a3e9054ae0262afa4538f297746537f1c9b7cVirustotal results 6.45% Quakbot
2023-06-15document_DA654_Jun_15.zipzip 254c640c59d2603a48a082f93ea3ebfce6390c3fae6b033652e5aa8220028762n/a Quakbot
2023-06-15cAcFN7sEYxPDvf.jsjs 0720aac76d5d13c900179f5f1ad5c2b613ee0c39b17d70d9108e065e1bc99671n/a Quakbot
2023-06-15pCiVsMz4iNW9G.jsjs 7b83652b94a8be746052fd68b71090991546fb71bc55457ff6877bea3ac548f1n/a Quakbot
2023-06-15JtrVlK7m5oCk.jsjs 848275640f7b887bf87cecab1420d01353d5515c9637cb2f473a4f832a368ba0Virustotal results 18.64% Quakbot
2023-06-158wOVy2rfs3ku.jsjs a1729b0820f2c3cd3cc236bd37583ab820782192e9967dc365dc6a6b191d2e62Virustotal results 0.00% Quakbot
2023-06-147blebN5sSIpb.jsjs a7ae65634bdc8d4d15c4f3b8717f0c3240588238c3ca7583901296a1f421ce89n/a Quakbot
2023-06-140EBljs84ssnes.jsjs f2ed5bc2adb67e707bae06222fb8a8ce81f5a13e96403c7acf0046d44d0e3220n/a Quakbot
2023-06-14WKq0cHsWrBqvPF.jsjs 9edb57ae5a950596772b3055ecd5faf17989d12d018d20fd1199d6643403ea52Virustotal results 0.00% Quakbot
2023-06-14docu_AC023_Jun_14.zipzip 7068de526b98d1022d6798cda257e3ca4a8416e4d55f044898ad96f0aebf56d9Virustotal results 1.67% Quakbot
2023-06-14docu_AD830_Jun_14.zipzip 3967d9aa8fe54211da93360f0bc961f59740eadb9453c7e4d57a99ea1e7acb26n/a Quakbot
2023-06-14qAwcmLsVnMHF.jsjs 37ca56a41ba3eaa4a33a8522caf8f9dac77bf9b55a1ae1a088674c9292415866Virustotal results 0.00% 
2023-06-14yLUeDdnjS5VqdX.jsjs 377b1b489a87ac0b2533791c282717dde556b9b636c7d2aba39081cd490ee84fVirustotal results 16.95% Quakbot
2023-06-14eBLD3Of1kHWk.jsjs b5c40040c76e177f3ff8104c1846ad28c3b2e474491f8e569925807d189959bbVirustotal results 1.69%
2023-06-14kwIUUlGrx3cP.jsjs 58fed3a739c1ab3b03f9eeb11efae107dcb008eb920fe897eb3a9672cf263917Virustotal results 0.00%Quakbot
2023-06-148DDLJ9CHBVL9.jsjs 359d2577521612961a6f0af93f502201d5668aa1757c7f29cc2615f4daca65b7Virustotal results 1.69% Quakbot
2023-06-14ia1PXomRcyyS1f.jsjs 022a002f99460822964864476d3d9de4dabc165556d9cc242d6bd7037e02e4beVirustotal results 0.00% Quakbot
2023-06-146so5xo00hMEaU.jsjs 996b3ffc7683c73b7d5e484f575aa3934f4833528da12bd8b27292ccbe563dbeVirustotal results 0.00% Quakbot
2023-06-14w3T5J32Yllk7h.jsjs 83be82e378dd748cecb0dea28355fe79c5ff4ce98045dc4022284dac40bcaf16Virustotal results 0.00% Quakbot
2023-06-1409I4BGJz3g1Xju.jsjs 3ef3f423cfaad4cc86c5258b280d3c1c020d407820afa4e62fa913f189ce60c5n/a 
2023-06-13Cayo5pTo4b98.jsjs bf1521a3ec608512bfd3342d16e8c7392aa729827eaae6d681d4285a0dd764dbVirustotal results 0.00% Quakbot
2023-06-13SVBnaxZLzhrhkY.jsjs a1b497bd1aced6b5fee5f8047389f7ee2356a9a964c8e5ecb4456cfdb4e66b46Virustotal results 15.25%Quakbot
2023-06-13fjptXj9py6ub.jsjs 6943b19f9924259d31e3d94974ae4df5ab4775e7f9cd0d1b8637690d65ee1badn/a Quakbot
2023-06-136h459f8N6J4jS0.jsjs 43afb4bd253fd9d1ffa42144eee4495e871bd9112db17c6d4f544fe8cc8b7c0eVirustotal results 0.00% Quakbot
2023-06-13I6Ayegc8tc5Mv.jsjs 675c342a1af08dc069a293b257048b4d2b9d06a88b3d1e41d2f91e95f53b5ee9Virustotal results 0.00% Quakbot
2023-06-13HUevUTxOkIc1U.jsjs f402b8848c5cdc6de1de79c42976ccf1b2e2b4f301d942d3c9eae9c63bcf5374n/a Quakbot
2023-06-131tb75ftPHdgBP.jsjs f964863b6ea96b481a85e460ec4983bb7bb7c1c2cebf398a80106c802c661d84n/a Quakbot