URLhaus Database

You are currently viewing the URLhaus database entry for https://rebelstore.us/csiu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659981
URL: https://rebelstore.us/csiu/
URL Status:Offline
Host: rebelstore.us
Date added:2023-06-14 09:02:10 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:03:25 UTC to abuse{at}serverplan[dot]com)
Takedown time:1 day, 6 hours, 43 minutes Poor (down since 2023-06-15 15:46:28 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_EA130_Jun_15.zipzip 301adbea0798d98ab20d66fa7dc8035ca9799b04140ac7cae8bcd4ed714ffadcVirustotal results 8.06% Quakbot
2023-06-15document_BF083_Jun_15.zipzip 98f5deb310140af7ff6b7935d8227b21ff335fb92ac1a50e0fe8482e3cce00f0n/a 
2023-06-152Ri2JyXpS1VNVL.jsjs 843f5c34f212cef8cd19f3822e9ff774656d34cfeb27977cafac196acefe4e13n/a Quakbot
2023-06-15rs3YOVxawrLJF.jsjs 55775426eb2fbf7559cba511cd9eac74023cb8a26172f8a395b932bf2b1e0373n/a Quakbot
2023-06-153Z7zEOVA0hQ3.jsjs c9b7027f3dc5249a7c3959be64583a14218c6c455bc97b7330569838dad16953Virustotal results 0.00% Quakbot
2023-06-153G7bIlZoLVoQ.jsjs 4ed4534d33d39ef4d2bc7e06d43e7cb923781d6c4633492bc3f383f32d6d7bb9n/a 
2023-06-15CfnGTAbbbLsM.jsjs 850b2fb8e69d1200a5d8ae89d45c83987265badb1474b459a7bc512323b77fe5n/a Quakbot
2023-06-14aBkyFXlTvuJ5Z.jsjs 05af50f1ce046ff06a1b8cc460e6a4c27704dabad038cf11bf063914d46503d4Virustotal results 0.00% Quakbot
2023-06-14docu_BE368_Jun_14.zipzip 38f4969252f953c0df18732db01e7c7b3196a253c76a9846121e60ca2ad495den/a Quakbot
2023-06-14docu_EF925_Jun_14.zipzip 10e566dcc281e6b991c1793ec7bb7fcf5340ff7c607fbc94780502a1567b8bc0n/a Quakbot
2023-06-14c0PoLmgModyi.jsjs 5510a8edd34fda8019955cc30e01b0a4bb18b239962c588c07d9c21ff95aacddVirustotal results 1.69% Quakbot
2023-06-14SErsDTdYAyzPj.jsjs 7f141a6ead781ea3893bbccd921bc9e80c75dd8a7edd2fa5b662b590c029d301Virustotal results 0.00%Quakbot