URLhaus Database

You are currently viewing the URLhaus database entry for https://petirtopan77kuat.xyz/cat/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659353
URL: https://petirtopan77kuat.xyz/cat/
URL Status:Offline
Host: petirtopan77kuat.xyz
Date added:2023-06-13 17:52:15 UTC
Last online:2023-06-14 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:21 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 18 hours, 43 minutes Poor (down since 2023-06-15 12:36:40 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15z0wgeDJKdv3Qlk.jsjs 375dde806cd9523842552419fad442e3d1cb5db36d60608a9bd0e757e11fb6daVirustotal results 16.95% Quakbot
2023-06-15uKsSxrauHmR80.jsjs fd15430bbbf90cb493f14be0df3dd7b7a6686459dda4d0601fc00b760b101a2en/a 
2023-06-15nEqaLAUxP3x2xT.jsjs 2740f14fa5948d32541e84f7c2719aa5f5e96e9093beb9cfbce3211d74d09b61n/a 
2023-06-14BSAulXwu33xs.jsjs 69b57b50b3ca6b4bf4288b9673ebdd7f4dcaeaad1bcc12a8e47b41e0311aea19Virustotal results 0.00% Quakbot
2023-06-14oQvWzu5zoJB7f.jsjs 51cec446fa27d41e2f49a25612211ede50ae7b577cd31cf4e9ac2f20b893f1f3n/a Quakbot
2023-06-14docu_FB867_Jun_14.zipzip 830da52c26957c558b2026ed46b06b762804bc40a9ec105ac2907792da111ab6n/a Quakbot
2023-06-14s8Qr4NnSLDwH.jsjs 3922d1b1d955cbeb3e393a4e1df563935c55fe5f545938c5a1db1a821a3c2b54Virustotal results 0.00% Quakbot
2023-06-14rNtvBobPaZqWwU.jsjs eea96900b352686f4027368ea486dc36e9a045408a1d0648815c483533f7c7f2Virustotal results 15.25% 
2023-06-14lZlIGLEkWMLJdO.jsjs 2c9753f3b2faf3e22fd3b6ef3be9c9edd4c22fbca372a9946b1fce7d7518c72bVirustotal results 0.00%Quakbot
2023-06-14d2rM1cvDz02x.jsjs 75030730085c9f4d5afe5987d5a00daf2c4b04fceb95ec0f241e271ee67b3714Virustotal results 17.24%Quakbot
2023-06-14CmnMmnT412L8l.jsjs 70486d3708fc4c5c848b9f5f3bfd329d77423f0d8e97e6ed80289da7e5e1675cn/a Quakbot
2023-06-14MyHIhVUB0umV45.jsjs 702b05b838fa4bb7e62f8c97a3823c6d813ddc3b1a1b44e83225def58d0022fcVirustotal results 0.00% 
2023-06-14KKnFl0Yd4Ri2Zz.jsjs 4589d0623c9ca1bd83875a78dfffdb75e1a5190a08aaffd90a6299cbc3834fb6n/a Quakbot
2023-06-140TKMaEA0QPc6.jsjs fdef38221e0225e6501b9bc784617eae4b6eab280721139c1618383cb3f0a6f8Virustotal results 0.00% Quakbot
2023-06-14p8rTxxIygpVZ3.jsjs 2a93b6d5c616cb03c2d5e9bef589dbb894396399c7b1987a896d552e5ac5ab7dVirustotal results 0.00% Quakbot
2023-06-14YiCTSF7vTKxcH.jsjs 17e0b63a9658844a7abe937e437ad78b32a0b831718cf4a8504c81f558243073Virustotal results 0.00%Quakbot
2023-06-13QhsY7LOvvegPF.jsjs 7273b75e139f3dd30809a4e9c1abeec754ee24b0a7f1ccc2333727449802fb81n/aQuakbot
2023-06-13ypDfRALVBDEW.jsjs a821e7221d10ecd07f5e0bb75652e33eead49e60ee39c0532cee0b43775b11e8Virustotal results 15.79% Quakbot
2023-06-13glNkUO81BxIZO.jsjs 2c0314076f91587df56b869725ec51994647a749840e798ee26427017bcd23afVirustotal results 15.25% Quakbot
2023-06-132NFaBnjTpB0hVS.jsjs daf0136e792cf3bf13bb53a8a40392f7ff38aa1bc870cc6a99b273f95c60d4ceVirustotal results 15.25% 
2023-06-13EvcG4ShDrxie.jsjs c560caa45b825d01ec9bf2dd4eaecbe7e34c80301c4c5ce8bdfacade0f7e3e4fn/a Quakbot