URLhaus Database

You are currently viewing the URLhaus database entry for https://getvalve.co/do/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659467
URL: https://getvalve.co/do/
URL Status:Offline
Host: getvalve.co
Date added:2023-06-13 17:52:52 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:55:34 UTC to abuse{at}contabo[dot]de)
Takedown time:1 day, 22 hours, 33 minutes Poor (down since 2023-06-15 16:28:49 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BD346_Jun_15.zipzip b49ddfc3ac4f3eee6f3d916e44827f02bb9bc447bfcb5a52586c0663c2549659n/a Quakbot
2023-06-15document_BD451_Jun_15.zipzip 60aa83135a668c1834e06a7af0c34639c0e6e01d4436d2cd4544a3c550f59278n/a Quakbot
2023-06-15document_AC521_Jun_15.zipzip c9644657972919045e8f52080ec06b37bb730aadf1a11e54095459328e8b59a7n/a Quakbot
2023-06-15BU3WtGWXrEYJ7.jsjs e1324d6a6474765da326d65ae5ade666b873154f82e2b80d3be721b1e87b872fn/a 
2023-06-1545b2BKgjrU4ow.jsjs 2dfa4d329b4df3b6cd02d77e4a36eb89631126a35d526433d87b622772df3622Virustotal results 15.25% Quakbot
2023-06-15X0zk5QtWgjrs.jsjs 327a4b48dfa16fb2efa6b8c5097d722de072c874a92548fdf73f06473e8dfe9eVirustotal results 0.00% Quakbot
2023-06-152DaaxOKctyjx0.jsjs c020b80a4b247dc41cb9f9dae71a6a597c42a0388eb6eb730bc3c0b16e03e621n/a Quakbot
2023-06-15NjKuPBpZJbL9q.jsjs 658b5601852cda3167017566a91b61b1b93b970b092be146e3d9606e13cf7225n/a Quakbot
2023-06-14JHFQrYdyG4tgo.jsjs 49c6bb4a14c70b49be707a1fdb82b374a14e3cd2dfb09aa87111a5c0286e689en/a Quakbot
2023-06-14nHbI1t2nrFIJzT.jsjs c4d67e01714e14f46603e0e760ac501063f32afe5e6e2365742f3aa9ba1779f9n/a Quakbot
2023-06-14LkOah4ZXvdS0Ur.jsjs c8c692255b433f79008d463eadba1850ab6cb484f32b787a318d3984d1740705Virustotal results 15.25% Quakbot
2023-06-14fIvLxb10p6eX6W.jsjs da1529f7e451e7221a561f3fdc0bab98ec5d8962b2173be96e62271564ffbe19Virustotal results 0.00% Quakbot
2023-06-14qjyYassKw6Qn.jsjs e552985ff266e1634976236fad4ea1b67d242a95399d255c9b984d18e93fb934Virustotal results 0.00% Quakbot
2023-06-14hQ1yZ933jsQWh.jsjs 1931cee49f7e8c236682655e3d81dd703ea9e3566bd3dce49a504331d2d747ffVirustotal results 1.69% Quakbot
2023-06-14Iv3XnLWg6OdX1J.jsjs db4f8c0c1ae2a40d44321117fd1fc22c03c44cddf6fe50d8058a3d8c370c38e9Virustotal results 15.52% Quakbot
2023-06-14Z0IrELlJPisg.jsjs 8f929428a217ff296d65c32306eda42ed9b315bdbcb403bfcdfa02f897dbf926Virustotal results 0.00%
2023-06-14A795Twp83dVuz1.jsjs d6e9212c85de9d72891dee0d7f8514417581aed4a91ad10f9e779c7cde7d52aeVirustotal results 0.00% 
2023-06-14MwwW7tTYf5j9r.jsjs 539cc769b7c26c392efde9f1b3b55419c4bb839db80aa01d2090c6ca2882d7c0Virustotal results 3.39% Quakbot
2023-06-14EzLOp9wfUlDg.jsjs 08b534781c91fa59da7feac81cd6e9fea528fdcc84bb91f19705a9e00ded819bn/a Quakbot
2023-06-14w2XFGWYd7VBylK.jsjs 6d0ca821cf16f5705471d86c3b715cefbd20f9caa3b98f08a88999d75a8f263dVirustotal results 1.69% 
2023-06-14rSvE2bEBC5lx9.jsjs 2f48117178c372504ce4f5b8cd3617f09a52334e9758a3d0c2ea4893e8c1c665Virustotal results 0.00% 
2023-06-14UyVdZNG1VBF0.jsjs d7995244004b6c7094809163e7f9587abc2a4759932ead8e535cad0e9011a40en/a Quakbot
2023-06-13n89HWHIyaiPTk.jsjs 977e2a9d32b2a1f31f955ae93c6ca9c68aed5c1383bbd537ed305d24b4b7fe2dVirustotal results 0.00% Quakbot
2023-06-13I6Ayegc8tc5Mv.jsjs 675c342a1af08dc069a293b257048b4d2b9d06a88b3d1e41d2f91e95f53b5ee9Virustotal results 0.00% Quakbot
2023-06-13oIcAZpyXBWTR.jsjs ed9e567f75b2292cbe3188606457ecba5295658cefdc14f02104de778ea16998Virustotal results 0.00% Quakbot
2023-06-135Ma6Pz5ZBEGl.jsjs 89746e03f20213f3ca6a69b03d54b2a2594b12cefeec6aada6048430008b9443Virustotal results 15.25% Quakbot
2023-06-13M23l4ylm8Nu9.jsjs 02583a853790764033b5696278dbaa6bf113b59d727050e4b11a63f5fc060da7n/a