URLhaus Database

You are currently viewing the URLhaus database entry for https://crimepatrol.info/sis/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660008
URL: https://crimepatrol.info/sis/
URL Status:Offline
Host: crimepatrol.info
Date added:2023-06-14 09:02:16 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:03:59 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 7 hours, 39 minutes Poor (down since 2023-06-15 16:43:07 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CB368_Jun_15.zipzip 21e657ca01d54cf0c4f59c8d81bf1a5540c0aba67e22ee10872071d94f67e8e3Virustotal results 8.06% Quakbot
2023-06-15document_EB528_Jun_15.zipzip 394351b86445a8ce2615aebde25f01137a9f575e861fe85dddd7ad4e530c221cVirustotal results 6.45% 
2023-06-15document_DE214_Jun_15.zipzip 92b87b66fe11074d6e5fdb1fa5a6f0dcb9318ee535d96c45ed3073a079caa12fVirustotal results 6.45% Quakbot
2023-06-15document_AD972_Jun_15.zipzip 46338ab291a395bc9b40a7bc653850ce4ceb39b5caa460330b300874eb0cb66dn/a Quakbot
2023-06-15MULaFWRJkYkB.jsjs 0845b4180780e37c91627b1c702dce58e69c0365ebf9346cc2d35a9ba1a7bc34n/a Quakbot
2023-06-15z62BGV9GFLZY.jsjs ff19e290296a6d232054d5660045fa7f561e7b06da32000a4a1da05883ef80edn/a Quakbot
2023-06-152sbNZgvqcWmy.jsjs f75e845ae4feaff3b8719269424438fcc1923c146f2ebe4da654447dad047edaVirustotal results 0.00% Quakbot
2023-06-15YspPkPhxvE3WH.jsjs 249849b1aeffc434d9a1f05daf0e3aa50d54080f53b00b68b194aedb10f6646eVirustotal results 11.86% 
2023-06-14F98z9EWsm0ROUz.jsjs 262eaf78d567d11299b8d1f30706cad650e9b3ac412be413b6369bd33b4b106fn/a Quakbot
2023-06-14JMSmeKiJrzLm.jsjs afb85c9c51d470f46dd4b82c541945ba0fbae550124eda1d3294f314e79e2af2n/a Quakbot
2023-06-14fCAVWJas4Gam.jsjs 0cbe398b65152584d012a4810760539112a458a77d66241c8314cb3ad69bc812n/a 
2023-06-14docu_FB673_Jun_14.zipzip 605350a70d59ea396d1f14ff4f17b45b5a1e9e682feb7c2bf9e77da2980fccd2n/a Quakbot
2023-06-14plN8vhzXlLAw.jsjs 57ced807ed0b808f86d5038dfce4c393fda85af6b8ddd5b952608bff0cb90973Virustotal results 15.25% Quakbot
2023-06-14UKlX9IpdokjWHm.jsjs ed9bae40483b816224a77502bb1babce59730bc71e77e04251f6ff79313b9ea4Virustotal results 0.00%Quakbot