URLhaus Database

You are currently viewing the URLhaus database entry for https://dqn.com.mx/ttdc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659340
URL: https://dqn.com.mx/ttdc/
URL Status:Offline
Host: dqn.com.mx
Date added:2023-06-13 17:52:11 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 19:08:05 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 22 hours, 28 minutes Poor (down since 2023-06-15 17:36:47 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BE782_Jun_15.zipzip 267847605c778c0877c52740b60b8f8cebef8806425990f0b28ac9fb7c174da0Virustotal results 6.45% Quakbot
2023-06-15document_FE854_Jun_15.zipzip 4ea1ad7a6a94e8eac2812cde16c357551ff76a9c912db50c19ea70cc2cb12037n/a Quakbot
2023-06-15SAZGxJyMgGL1k.jsjs 377e4a1979364a0b138b4f396b793edd893a7c7603ed8101c14cbb85b863dc61n/a Quakbot
2023-06-15F9h99btqCK0i.jsjs f64620c1c302a7bfa30d97b3a7b55d1f84fd0cf1e4c8729e9df57176557085een/a Quakbot
2023-06-15Evbhr4KJz4Ruap.jsjs fd450cc9d3bc06782edac878682ba7850a42fb1a083c18564f722aab22534d8fn/a Quakbot
2023-06-14uIQQuZlPA504jq.jsjs 8977471657ed0fda88b96d3b99e2d069c2f51750ea3d5aa86ee6ca6a928ba198n/a Quakbot
2023-06-14XI5s0iSqL03cCW.jsjs edd589ba57694bad111932ddbbc5e6d55edfe1143233ad348ad7de4ab8a3542fn/a Quakbot
2023-06-14a4YQ6UxZhsp5tr.jsjs c1f1fbad43a84d906bfce43674da268bad184919e8ee6d7a1b903f4270576f79Virustotal results 0.00% 
2023-06-14oVL65HfZkVy8.jsjs 84bff012a64a724df289bdfcdf5910845c391c2ae431a4c8a3fc3a6c790540ffVirustotal results 1.69% Quakbot
2023-06-14OQA65CIp7zjk.jsjs 246a706894ad22b1ebedccf38cbcd08e8756bd3209ca1b2f424a296ef26b74edVirustotal results 1.69% Quakbot
2023-06-14s1pWQPx4hMXJ.jsjs 24d9537d3b8010f7ca4629170de02d72a16212bfb3eb11348c80aedfcdfaea87Virustotal results 1.69% 
2023-06-14wfKurfoyoyC9f4.jsjs ba8285de74aad64490ac8de5c7f30f480041e621806ab50c68a772cc37570ebaVirustotal results 0.00% 
2023-06-14HiYLsDjAycE7eG.jsjs e9463170b553a9a93634d494cb40fa7cb1262eadac1d486ecee9acbee098cab6Virustotal results 0.00% Quakbot
2023-06-14phC0hqjJ4cwc.jsjs 533f9aa74aaa0c848ff790fc50b2dc869344e5a575fd4a9fbc2af192b6b3c76dVirustotal results 1.72% Quakbot
2023-06-14flUJRnh1qsDL.jsjs 15d963ffe4306270c88643d8aee76a953e51f5bfe7f1831c6bbb67a37c559e32n/a 
2023-06-14XiDoiQZTeJ449.jsjs 9ea92b344586ead491a8abfffa283432b9119fdd13d753e83e5dd55465d0970fVirustotal results 1.69%Quakbot
2023-06-14a4Shj8mMCjLAS9.jsjs 357fb67496f0a6f203d49c244ce9020183f88da020ecb35a64a860d65bfa6712Virustotal results 15.25% 
2023-06-14J3kta9ixUPd9g.jsjs 6f0ec879319b236a6b0a8d14638db2ed810c37f18f4aec29f409112726f6b740Virustotal results 0.00% Quakbot
2023-06-13VW2EYAO9FPBO0r.jsjs 53c1fa6e950d5688bb7ecd26f397579a37fcfb28d12869a0b7f7c4899a9d6cc8Virustotal results 0.00%Quakbot
2023-06-13Hk3ps4STjnZYt.jsjs 2b80621d811a6d0d4b3a3439ff79280fdcbaf1dfa805fa787197cb4fa010affeVirustotal results 15.52% Quakbot
2023-06-13bJQrQIPQrhCO.jsjs f3c89b57ec700157818293b4ab3cc6998e1cc99bce9e06431180baed8e8f8333Virustotal results 0.00%Quakbot
2023-06-137nbSOUWPm3M3C.jsjs 04e6eea889711e2622b0a0d711caacbd10814d4aa2dc52f1660b0b4dfca55161n/a Quakbot