URLhaus Database

You are currently viewing the URLhaus database entry for https://3ileadfoundation.org/utte/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659468
URL: https://3ileadfoundation.org/utte/
URL Status:Offline
Host: 3ileadfoundation.org
Date added:2023-06-13 17:52:53 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:55:36 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 22 hours, 6 minutes Poor (down since 2023-06-15 16:02:18 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AF798_Jun_15.zipzip 97e4cdfaa70dfb54ce3e07605aa8f13b85fff93fbf9a7e72ec7d80c6a2afb6e1Virustotal results 7.41% Quakbot
2023-06-15document_AF163_Jun_15.zipzip 27578d989ccf6bcd51a8261878473997d42e4d746f75b0447ded2238c6bc0c88n/a Quakbot
2023-06-1594yIfIL9vaoKnN.jsjs a214834a9c87e8ecd2f8b01100bdf09251b81f5f6f148931b7b7858a538edf4bVirustotal results 15.25% 
2023-06-15arH87BiqMSyl5X.jsjs 161529cb7c28baee604d4b0212b378951170393b1b8615ece1a6f5c18ee95793n/a Quakbot
2023-06-158G4bhDz6c0lkOD.jsjs d96fac49ed9b39ccb06844298d45e4e4740d718e0f9ee82262387850201095eeVirustotal results 16.95% Quakbot
2023-06-15DJb6uWYDKgHD.jsjs 453a9941bc55f03cab2d4e620a2003e1a392d8eeab3dbe75b5cd9d3222332e29Virustotal results 18.64% Quakbot
2023-06-14DegfPnNkaEUKfU.jsjs 51fc3668a82a3750a2ab447d9790b66635fef171b7c7aaaf595763f52f868fc9n/a Quakbot
2023-06-14EKQrmyk8jpK6.jsjs 8c67f76ce9c1f02e2081111bafdde75ec020bcd302ceebc22054b2ff8cf4d1ecn/a Quakbot
2023-06-14x72LTXXV6j4X.jsjs 084dbb041811f4809ed27cb8f8b31232d1df8bee00bae9a1b38eefeb2f4ffa53n/a Quakbot
2023-06-14docu_BC469_Jun_14.zipzip 87ea42856243dd112fed001353a87de4f12f5d3f97d6ab6129d9aa9a22ad384an/a Quakbot
2023-06-14docu_AE576_Jun_14.zipzip 75b5df06f02b8a33c070e2d639e71e5d39dd00a092db107109ec362c4b34af1an/a Quakbot
2023-06-14iOQH0q6uHoRu.jsjs 7e1cab198ebdfb8e9928b8108e9c8018d1c7dcbb4d9097f49a04c3187da3c7cbVirustotal results 1.69%Quakbot
2023-06-14IvqEQRq4cyAkAT.jsjs 851fd360e88d59579915ce7885ebd7f385f17accfcd3d06c321dbea96e69c960Virustotal results 0.00% 
2023-06-14NlEyVR9lY1Wr.jsjs 759ddb59654de37cb3dcb7bd281a2e6ebd99d4b74987d6723dcd224db39dc879Virustotal results 0.00% Quakbot
2023-06-14bhuY8XwdY6sI.jsjs 4e57148bfbd39f2bd7256784c1002c691b566dbdad8bbedbc16aff1597617529Virustotal results 0.00%Quakbot
2023-06-14I7Vsj6yOmGZT.jsjs ac30912298480d45bf0f9e1c035e96da5c56cda83c13d501510cf812d0e8d113Virustotal results 0.00% Quakbot
2023-06-14e5rDLXvL1rud.jsjs 63858de90c1486d4ed0fd0bf91ddb45d8623040cd5d3c6643eddf7f95251d03dVirustotal results 1.69%Quakbot
2023-06-14foQbgV8KxCFJ.jsjs 0a8bc6c8352e1a777d3c8b26db1533e4860f1b299862012ef6d766312685e66dVirustotal results 15.25% Quakbot
2023-06-14RMdBoYMV4lt8.jsjs af421ce80f44c8aa9ee3baa364b9e4b541e48198fe96894b39f62297eebf1427Virustotal results 0.00% Quakbot
2023-06-14AlEVJ9ZGBQdVr.jsjs ad89128882cc5045364c6ec03dd8bffd34f16bbfd341d0dd13fdce7a706e64b5Virustotal results 0.00% 
2023-06-14HvqXMMIOshKq.jsjs e6065951beb74e637ffa5b8ef754320d38bf53274255f15332f451291988c55eVirustotal results 0.00% Quakbot
2023-06-13otBbHGiWa8zDa.jsjs 69f93a6237243fafbd9819b0e9f48146bc2bb54273b0f7ef5815edf7b0fc9626Virustotal results 15.38% 
2023-06-13SQpYg9aMcNQvc.jsjs e918e17a0a639c0f284a76059249a8398b71eb09bb54e4409fe6ae526a332431Virustotal results 0.00%Quakbot
2023-06-13aYQa9wQyAZZ1.jsjs bc64caf34f92e2e6f063ced2c6d9e82ecfab18b7aeee5767de6094fd960d23aaVirustotal results 0.00% Quakbot
2023-06-134ngaavsGew9ep.jsjs 9f254a99c8f47a850e92e8198602d17bff5202ad9baa1fe39877c2e36db17d9bVirustotal results 0.00% Quakbot
2023-06-13LSN6mvp5DISVw.jsjs 011c46b580421e8680614d86ff33170e0eba2a8e1c98e6f2d87f779fa987ef3cn/a