URLhaus Database

You are currently viewing the URLhaus database entry for https://bewebin.com/ciir/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659254
URL: https://bewebin.com/ciir/
URL Status:Offline
Host: bewebin.com
Date added:2023-06-13 16:33:17 UTC
Last online:2023-06-14 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 02:14:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:18 hours, 21 minutes Good (down since 2023-06-14 10:55:50 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-14GXjIvHZdmODq3H.jsjs 3b4e67fd941416d3d7c685fa8ce18c84f2b82364abce51234063e2482eeb801bVirustotal results 0.00% Quakbot
2023-06-14n89HWHIyaiPTk.jsjs 977e2a9d32b2a1f31f955ae93c6ca9c68aed5c1383bbd537ed305d24b4b7fe2dVirustotal results 0.00% Quakbot
2023-06-14JpJEh5qP0QC0n.jsjs d578997e38238c6ced02ce0bb621168c2109002d185e063aaca9acbcac8e42cfVirustotal results 0.00% Quakbot
2023-06-14QuC86XQVHCJ9y.jsjs bf01a7146dfe92bf81f1e4dc18cd8f7bc4d3c66360c344aa8183336483d36f70Virustotal results 0.00% Quakbot
2023-06-14j9vV4hXPweiQwz.jsjs d388ac13232edae5a470d05c1344730f7dea4ecdae32a62247c4aef2caea76e0Virustotal results 0.00% Quakbot
2023-06-14GV1wJwTtmyr9.jsjs eff9d6ca2a7a7c9dcee86083137fdfe4fdf760faf1e81355857e68939607b1b0Virustotal results 0.00% 
2023-06-144l3GApqQj9p6p.jsjs 4bd308b464bd0192a05d5c05c2860361ff6a14f25e07609ea63fccf500e824dfVirustotal results 15.25% 
2023-06-14a4YQ6UxZhsp5tr.jsjs c1f1fbad43a84d906bfce43674da268bad184919e8ee6d7a1b903f4270576f79Virustotal results 0.00% 
2023-06-14ZqA3jDHesSWvp.jsjs 9afc07d212d7e028829b7ee4cd644b0449b2a3b42e328211be67c040c9ab8981n/aQuakbot
2023-06-13BkbxLOnlznvoBr.jsjs e6384532d872253710ba3a3f680a2def5c60a79bd079d3e1385e1e4410d19bcen/a 
2023-06-13lFCT0hzvyoX00.jsjs 3bbd595b90e2986fc2d5e29a671af3b529f680f4464340386790f96ed588ac17n/a Quakbot
2023-06-13o8ZhTR2TMTtVBu.jsjs a4723a14b0f4cb97c6c12e88d9350a036a568b5b9edd60ab1f21ace5c41d96e0Virustotal results 15.25% Quakbot
2023-06-13UTrf96UpLmKX.jsjs e2d52c6111c68535f7c2841b3698a29cd59ed137e71a39abfc9c95ed25a4e255n/aQuakbot
2023-06-134ngaavsGew9ep.jsjs 9f254a99c8f47a850e92e8198602d17bff5202ad9baa1fe39877c2e36db17d9bVirustotal results 0.00% Quakbot
2023-06-1337ZkaJRCQ6AfzS.jsjs 6fa5e91f83aca5ec1ba097f04ffc440759eb42b64d28687afdf548a7b75b1ea9n/a Quakbot