URLhaus Database

You are currently viewing the URLhaus database entry for https://onehornsolutions.com/ue/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659380
URL: https://onehornsolutions.com/ue/
URL Status:Offline
Host: onehornsolutions.com
Date added:2023-06-13 17:52:24 UTC
Last online:2023-06-14 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:57 UTC to abuse{at}ioflood[dot]com)
Takedown time:7 hours, 50 minutes Good (down since 2023-06-14 01:44:27 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-14QRkhgwP2EQuPN.jsjs e008b0438d7c2b48ff5c96bfe63b2ac51ae9eb0133be04fe97c1982fd27d9bcdVirustotal results 0.00%Quakbot
2023-06-139pQLeKXj1gpKb.jsjs 010bbb513a4707293ec9d34090f4b5ffc3ec2a42bf7d756ce4d291db152bd4cen/a Quakbot
2023-06-13IP0wvsrCVEE20Q.jsjs 6575c5d9d1c6fad2d3f23546b060ddf483873f8cc9747bad7db891552ea28098Virustotal results 0.00% Quakbot
2023-06-13gp1FuHgeRHPbxY.jsjs 3e1667b0ade50d60845228578f60a6540cdbd21bb0bf6a52bc186a239d809409n/aQuakbot
2023-06-135OZsddt88kWskJ.jsjs 2f611d2bbed4eccbd77cefc020aa9de246c8d90313f37e8cb63f8048557a23eaVirustotal results 0.00% Quakbot
2023-06-13Hss8Dm2Zis2Gs.jsjs 6e86f26862c886b01d7e28e34077d50ee7d167a4a5925ad9932469d5b12f2622n/a Quakbot