URLhaus Database

You are currently viewing the URLhaus database entry for https://gbedemfb.com.ng/qu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659357
URL: https://gbedemfb.com.ng/qu/
URL Status:Offline
Host: gbedemfb.com.ng
Date added:2023-06-13 17:52:15 UTC
Last online:2023-06-15 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:34 UTC to abuse{at}whogohost[dot]com)
Takedown time:1 day, 16 hours, 21 minutes Poor (down since 2023-06-15 10:15:09 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-153OLtwL4gI7W1N.jsjs b481f238d37c5fcdd3d0ae1a7ee3d39b237ea8d7d58711781d81d36aceb28685n/a Quakbot
2023-06-15HAvE2FfsM5qKN3.jsjs 08bfcc3151c4b647717d7d7ebaf3616bca9efbc76704fa45c1f547a8a9e32e07n/a Quakbot
2023-06-14H00ezRg9LKmf7.jsjs 9bc5a0a35c4ef67da8b9765f54383305d85f4c2458778c3eab27e285e460a0c7n/a Quakbot
2023-06-14PJoy6aupHRoUaH.jsjs db27f83cfaf71994fd87c6aa7c859c9f68ece94cbf1204cb4f19aa30086e9009Virustotal results 15.52% Quakbot
2023-06-14Ytxsn18VAyIa.jsjs 37c6b428c6dac5415c0b35410a7aced9d2053d27b962431df24c4173c93f8523n/a Quakbot
2023-06-14docu_AE539_Jun_14.zipzip c01fab0028c58c1e03009d719a124bdead3562f3cf2917d416b2adc5310640ebn/a Quakbot
2023-06-14zQNTrxxB1Yf6.jsjs 92438b342307b31fd212839d246cee15533783e63e9f747fe50672447a54078fVirustotal results 0.00% Quakbot
2023-06-14GydMf1FaNMbCP.jsjs bbfb0ba41ca93c14c1ce9a65464fbee472fb0f2eab52dc47eac07d2ff59ed4b2Virustotal results 15.25% Quakbot
2023-06-14p3Zli3jnyEeqyj.jsjs 36575e26a13247c0d8813e4119159006fbb88031c6b5af424ee0b44ccead0118Virustotal results 1.69% Quakbot
2023-06-14gaNVzsb6EH1W.jsjs a86f7f0a7aef936e4ac1b4c673ce659817b0ba17a76be06236ee2fd64d88aa9cVirustotal results 0.00% Quakbot
2023-06-14SJ6FuMfpe1Gj.jsjs 85aa6a26b394da306e21260aa86bb2f36550ead1086c06ffed11cd86c214cbe2Virustotal results 0.00%Quakbot
2023-06-14B4BvFUZb26S8fq.jsjs a543796dce447dcc8b2ca8e73cdc12730c3b214ce2f0431a6ceeb8708065ade6Virustotal results 0.00% 
2023-06-14sDTJ4y23w2iN.jsjs 429f40203cb0309daa8ae8225006da50beaf1618be71766fade353cd796e365dVirustotal results 0.00% 
2023-06-141NXgj9fMqw60M.jsjs 00d47ac53e27bc2cedc4ec499705573d3ec883edd7cd128b1c27ca814147ca76Virustotal results 0.00% Quakbot
2023-06-142NFaBnjTpB0hVS.jsjs daf0136e792cf3bf13bb53a8a40392f7ff38aa1bc870cc6a99b273f95c60d4ceVirustotal results 15.25% 
2023-06-149QqtuMZtH5d8z9.jsjs 570a45bb6b33b7a8a0fc9a63a4cc8c50cd2b12923de836ef58cd94c3e60ed5c6n/a Quakbot
2023-06-14pZ8TwM6c6qJutR.jsjs ffb17a669898e1dcf650a3f29cd996e7616f2fb2fc74686e07b05d959b4099a0Virustotal results 0.00% Quakbot
2023-06-131ZvYN1IiHOyWvd.jsjs 6f76135a8f0906aacb09a6860dd6904d4209f32d89b8d7c5cc108c34fc8bace0n/a Quakbot
2023-06-13xUgIwlv0zFSDb.jsjs 714d3253894ca7c971ac2c4d09c65858cb003f9dcfeec45eb0abc7c54ea23309Virustotal results 0.00% Quakbot
2023-06-13otBbHGiWa8zDa.jsjs 69f93a6237243fafbd9819b0e9f48146bc2bb54273b0f7ef5815edf7b0fc9626Virustotal results 15.38% 
2023-06-13SErsDTdYAyzPj.jsjs 7f141a6ead781ea3893bbccd921bc9e80c75dd8a7edd2fa5b662b590c029d301Virustotal results 0.00%Quakbot
2023-06-13G0b66yOa9kD3v.jsjs b963868d82f7d86824006963e689109a63d9a98c5531e84a90bb2d25071b15e8n/a Quakbot