URLhaus Database

You are currently viewing the URLhaus database entry for https://alburjshemagh.com/qu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659443
URL: https://alburjshemagh.com/qu/
URL Status:Offline
Host: alburjshemagh.com
Date added:2023-06-13 17:52:45 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100132781 created on 2023-06-13 17:53:08 UTC)
Takedown time:1 day, 23 hours, 51 minutes Poor (down since 2023-06-15 17:44:26 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CB369_Jun_15.zipzip ba8106a22c754451290d06176a1e2a2ed0ea72f4c919cb9c7ce3b792c9dca196Virustotal results 6.45% Quakbot
2023-06-15document_DE108_Jun_15.zipzip a739645788a95ede796f883defd315ab0d3a931a9fafb31a265437abdb0e2030Virustotal results 6.45%Quakbot
2023-06-15document_CF436_Jun_15.zipzip 4b5ec9bc2095f1e2a902ef11d4312105278cb95c029df5117786161a8ba3a41dn/a Quakbot
2023-06-15document_AE956_Jun_15.zipzip 4ff9848b211a8f3e3e136865a27b925765e0f9b52092881f49e293ea1901d7ebn/a Quakbot
2023-06-15RG1a6NjoKYcA.jsjs 1941dea86324080096a5ff79c0b07dc78e4cbca40890d5bebaf1bb7173034973n/a Quakbot
2023-06-153CsffSAuB9Tb5.jsjs 0de4164e7625f2078623212116167e87c8b24334ff7b0458f04a71033c1c2a35n/a Quakbot
2023-06-158DrVwI8y5VGFYQ.jsjs 499d8b75eea7592d8d86c29a2a2500de12786da22ef51336a08c5bcb597e0303n/a 
2023-06-15C9xiAnKNcXqi1.jsjs 02658b8a67c9b0826360f973b797ffa4b5db7e2aa9a6822aed51df90f67caf2fVirustotal results 0.00% Quakbot
2023-06-15fah9r0vDkeRy.jsjs f205521b9032b5146f85e512ed07b3a7f67e2b6a7e8603c295fbdff019d0173an/a Quakbot
2023-06-14EdbQ4z4eSGWNW.jsjs a746dae71c64816c8589a6613765cf05b992a6a85e1f04392f80b469ade10eb7n/a 
2023-06-14qvVhzifN9JwB7t.jsjs 51a7099d8749c533c79d4363224e1dd9f371e9dd664d22cc2690efb3a6759be8n/a 
2023-06-14docu_AD652_Jun_14.zipzip 3dfc805afae09c5a27fa55caea231b0c83da035b8b4cf29a03cb525dc545e735n/a Quakbot
2023-06-14uY5sdUUu0rrCLV.jsjs a60aa9ddb713bc92ac20d9c0a07a957f647360609a08fb0a057ed428cd483866n/a Quakbot
2023-06-14EE22XfspgzgfbF.jsjs 59eb669a757058561ea4c07b922431289017a7bce6a4f8a1fac76b85c30ece5fVirustotal results 0.00% Quakbot
2023-06-14AxRwQ0w307yAs.jsjs c4e16cbe8bcb1066d85844e23bad6796cbbd4a68bc00ce9d63ee4201f63d88d9Virustotal results 15.25% Quakbot
2023-06-14HNd1yYNoxyID.jsjs 412d8ed2b5c5aa3eb0487ca19b47426c2631fbaff5900be52e3c978477d52500Virustotal results 6.78%Quakbot
2023-06-14DLD4SPtBb6HWrV.jsjs 8f7679d31a4eb01d2b0beab23c6f098962f44715b6da3064caf68f433fb7d340n/a Quakbot
2023-06-14JuP0BzKVqHSdg.jsjs e03dddc50009d64296028b01adaccdb4df369e4dcaac06a1cb0a3acaa046a9c7Virustotal results 0.00% 
2023-06-140TKMaEA0QPc6.jsjs fdef38221e0225e6501b9bc784617eae4b6eab280721139c1618383cb3f0a6f8Virustotal results 0.00% Quakbot
2023-06-14YKGhWCPKleYeu8.jsjs 4e34eb94bc4d4b80cf3a777941e563a8485e25b958e3222f3ce32908b1b6dd1bVirustotal results 0.00%
2023-06-14bK1tUo6KZFoz6P.jsjs 9efdf759a7bfbb48310e66c322b48ff213edac8fbccfa22e67e736ceaa0a79ddn/aQuakbot
2023-06-14ZBnCgr0TgNBx9Z.jsjs 820bcaca6680e62df21937deb4532788dab7cee80bf3aa6695b169dc4ba41c71n/a Quakbot
2023-06-13IPlWrbQZlcxuZ.jsjs 5bd5540f6d3a9e5c60722dc3244db3c1458ca0614f1355bd03120b5b5679f99fVirustotal results 1.69% Quakbot
2023-06-13wRfKY3wHdofWd0.jsjs efd9d13ad982dddd3f52e753dbc6306173d53ffec9664190df0b5fa099af0966Virustotal results 0.00% Quakbot
2023-06-13a4YQ6UxZhsp5tr.jsjs c1f1fbad43a84d906bfce43674da268bad184919e8ee6d7a1b903f4270576f79Virustotal results 0.00% 
2023-06-13VSVpARyN3cztLX.jsjs ab548b135d975073153ac01adbb7a92eba6c9f4f6afde5f553b55e158ad524ebn/a 
2023-06-13LZJPLhTUOl0dZ.jsjs 5cd15a5947d6feb4ebe67137cdec8600bc585ff8c1343034bb040df86a0eb3c3n/a Quakbot