URLhaus Database

You are currently viewing the URLhaus database entry for https://er4uecom.in/spir/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659460
URL: https://er4uecom.in/spir/
URL Status:Offline
Host: er4uecom.in
Date added:2023-06-13 17:52:49 UTC
Last online:2023-06-15 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:54:40 UTC to rajat{at}emaxglobal[dot]com)
Takedown time:1 day, 17 hours, 56 minutes Poor (down since 2023-06-15 11:50:42 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15XZNFYmZqgP6g.jsjs 82037ba152360f3385a13b444d07d7f0a26b18ad535c6748acfb514a0b505ba4Virustotal results 16.95% 
2023-06-155R0cuY57t7LAp.jsjs 95136dbf6b0144ddca36f8350e1181005977a52480179930c8d391bcd9ac50ecVirustotal results 16.95% Quakbot
2023-06-14dicrYUfPFzHVy.jsjs fd574ac13a8fc1c312887c2c077238744ad8c21fb6f7e05be5f48803710a453cn/a Quakbot
2023-06-14T2KagIr2h3FODb.jsjs 7c3c68cbfe396127160a25bcf3af6eb800dc5e9a191cb02e6be2c98f1a472e57n/a Quakbot
2023-06-14uTZT6awaCsj9K.jsjs ce1127c64a3e29c6be857e4f793bf0b8573dd01b420c048021c8da87b654fbd8n/a Quakbot
2023-06-14aoPXgpWCNysB3.jsjs 9dffdfb73cd94cf534a0444b68b07a654a57ff11c16790e6ffb9d90199705232Virustotal results 1.69% 
2023-06-148NBpht0CPmrJP.jsjs e67cc251b0099e6448533274e9bbee0b22390af8c47a92bb6c7fd8fbd5725285Virustotal results 0.00% Quakbot
2023-06-14tDSIPtjiHVjMI.jsjs c7b1f5bdba77ee38d49324f1e11eeafc16f5c6d58fb0f12be4290708730b5765Virustotal results 15.25% 
2023-06-14N5HWbSLuuyIsLC.jsjs 52bb11ce6f9126bca631c0ba9116d446457e2dd77d29a343e5a300e0e5303b46Virustotal results 3.45% 
2023-06-14EE22XfspgzgfbF.jsjs 59eb669a757058561ea4c07b922431289017a7bce6a4f8a1fac76b85c30ece5fVirustotal results 0.00% Quakbot
2023-06-14SCotO65yEowD1s.jsjs 2a9e4637145e8353e03ab6ba4e569a4e06ca4f97e0e4388e5fc1037a6882ee7en/a Quakbot
2023-06-14IDzOKgUMidTj.jsjs 2e6c65708101978493d33039a24987a1b46b65b3c1795df913b4564efad64b7eVirustotal results 0.00% Quakbot
2023-06-14NDdISsOrDonoW.jsjs 9a14e3ebf641ba3eef36d00826eea3670cd62bf4eedda4dfd4cbca7563b65115n/a Quakbot
2023-06-14esjzcrxWKBqy.jsjs 96984f4d92e891aed7f951855292c8b034afe2e6683651f85f401cbe8246d889n/aQuakbot
2023-06-14Md175YlLRr2i.jsjs c72f9d4985280477c1b57234ed6fdb9d760060d765c03db312c206ea35e8cb98n/a Quakbot
2023-06-14sHjEM3p6UJmT.jsjs 96a4f008ed8c404dcdd6003590e5453eff2affe0dde4845a3dc681ebac85fbf0Virustotal results 0.00% Quakbot
2023-06-14YXZBzyvUHeTN.jsjs ad95395315d5caee130c970112020092bef82a19e7f1c607a5c81a2152a0bf44Virustotal results 16.67% Quakbot
2023-06-13ERbvdDZCa5dve.jsjs d4daf2d217a0fcf8ff210461b5617f3591082c15dfadeb9c7dace10502243b45Virustotal results 15.25% Quakbot
2023-06-13OU7DaQPhbRfj.jsjs 560a5ab4cce6e9d0734472d58f8bf3852a5298769bfed40509ac71dab225d411n/aQuakbot
2023-06-13Jtz8vkOjVgwJ4J.jsjs 91307559f707be501540666487c1292b396caeccb87b9cf49cfd05413a06c949Virustotal results 0.00% Quakbot
2023-06-13GXjIvHZdmODq3H.jsjs 3b4e67fd941416d3d7c685fa8ce18c84f2b82364abce51234063e2482eeb801bn/a Quakbot
2023-06-13MwwW7tTYf5j9r.jsjs 539cc769b7c26c392efde9f1b3b55419c4bb839db80aa01d2090c6ca2882d7c0n/a Quakbot