URLhaus Database

You are currently viewing the URLhaus database entry for https://priscinsshoes.shop/ua/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659371
URL: https://priscinsshoes.shop/ua/
URL Status:Offline
Host: priscinsshoes.shop
Date added:2023-06-13 17:52:20 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:48 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 22 hours, 22 minutes Poor (down since 2023-06-15 16:16:20 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BE279_Jun_15.zipzip 08068bc18fa1c333600a54b77fc128cdeaf9fff983cfe0b52e87035842224d1fVirustotal results 6.45% 
2023-06-15document_AB756_Jun_15.zipzip be33f809582e0f32b8c3b9e68b4d2d52eb27aaa5a853e0dc774e45b05bb55954n/a Quakbot
2023-06-152UWZfh82tR53mp.jsjs 384eab496a0fdeebb44b0985229d049f490711c39a2bf0cd6a44ac66c49f4502n/a Quakbot
2023-06-15tx5SsojWVJ59V.jsjs ce1f161d50dfa52ed8d1baf20a9b3052421db0a342071f86a4d471a8040de51cn/a Quakbot
2023-06-1556oV5vK0Avt8.jsjs 46e45d43379f39847899f7fbfe9b307aae63a6e74ad4d450e4cb06f082e5f851n/a Quakbot
2023-06-15jwZ5MlB99GB2.jsjs 81afa33cad438ae3ccee9a300452e388134f669b145367de63095214183206fbVirustotal results 0.00% Quakbot
2023-06-14fQPhB29p1i0Pf.jsjs 8a2e41a0dd7efb0dd51e5fb533c29ebffc9618eb126e1ac2e9799acff164ad68n/a Quakbot
2023-06-14ptNViiJhrK0t.jsjs 40783143a239b8426fc0a10466d7ab7e62bae9b95a0e9d850334b68eec92e77dn/a Quakbot
2023-06-144lqfcLiov2Rq.jsjs 95b2a85db1d81ac4ce3985bd6be912269ea3caa6cb5af7755220a75e5e013e69n/a Quakbot
2023-06-14docu_EB853_Jun_14.zipzip 1e87c0cd69ac535d64b9b8c147b0fb246730cb7e1c1dba8fa4d20b47d8d9cb73n/a Quakbot
2023-06-14docu_AC745_Jun_14.zipzip ca304b131ad882a367b4db9a3db59c83457927942e923b686d3d563b650ed920n/a Quakbot
2023-06-14Rmg2vNmk1E0Og.jsjs 049aa20cd3665454320fc273d518cb89bfc984a9662ba6e5207407953f5cbdcdVirustotal results 0.00% Quakbot
2023-06-14HiYLsDjAycE7eG.jsjs e9463170b553a9a93634d494cb40fa7cb1262eadac1d486ecee9acbee098cab6Virustotal results 0.00% Quakbot
2023-06-14j8Ic7ygho8htk.jsjs 71085c763c95e9c210e090f96ac8540db019a10b589407c7f73d3c62615b07c9Virustotal results 0.00% Quakbot
2023-06-14W9c2GBeUrOQF.jsjs d5799679892f2d41682602153ef3a6cb8606cc55b642e23e1d0074acdebf324fVirustotal results 0.00%Quakbot
2023-06-14f2iEjQ7Bt38Hf.jsjs 14bd8dbe7b00ada45c018c3eca47e5ec63bcd3ca917a8ebe3028265dbfe860edVirustotal results 1.69%Quakbot
2023-06-143wGX03nKPreYM.jsjs 2189fc7d4919821aa3397ee92a9388a0c68cb5e9609bb6e5bba88da219126306Virustotal results 15.25% Quakbot
2023-06-14XMxEMIYY49oF.jsjs 000aa5ed2b757af805ba8809fe96f679a4571ea36875eaa5e5edd586488c9438Virustotal results 1.75% Quakbot
2023-06-14U0LpsMzh3qD0y.jsjs a0825685c4f9d782fbe5f04b55d7345e0313296072883d2234a0f593e76e25d7Virustotal results 0.00% 
2023-06-135x5GXce4rxIQ.jsjs 18586a9d694fb77bb4a0afede289c35ff33b6a25628e603288993191760cafe1n/a Quakbot
2023-06-13ALLrayjgN8kR.jsjs da5aad281ed680a522be9d0a37289be6db116abadd41982734f8d00faa22dd05Virustotal results 0.00% Quakbot
2023-06-130cL20RVR8z6t.jsjs 375ea3deb01c54281ba1f5b42d7de80aeb35ca33e18a3b95baa37a8a059d01f8n/a Quakbot
2023-06-13M23l4ylm8Nu9.jsjs 02583a853790764033b5696278dbaa6bf113b59d727050e4b11a63f5fc060da7Virustotal results 0.00% 
2023-06-13eozfQ66pGEjjz.jsjs 0e00ded5f9ad6662d955770f086ae1ed52d0eaac9375c87f9ca0e2d2ed2145cbn/aQuakbot
2023-06-13F5WaGVReLXmi1.jsjs 3dc6376b466935f3e4274c9b2512a32fbf78081607bbb34764f18674b3f487een/a Quakbot