URLhaus Database

You are currently viewing the URLhaus database entry for https://krayflex.com/eao/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660037
URL: https://krayflex.com/eao/
URL Status:Offline
Host: krayflex.com
Date added:2023-06-14 09:02:22 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:04:32 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 8 hours, 48 minutes Poor (down since 2023-06-15 17:53:08 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CA109_Jun_15.zipzip d57ca37b6219390110344d4797c5d33aef44ca82d7d652946cfd6a9f8bd63998Virustotal results 6.45% Quakbot
2023-06-15document_EF276_Jun_15.zipzip c46d3492fb5589695c115cfab615a04dcb51d29717f94b72179ffe381bf7e4d5Virustotal results 8.06% Quakbot
2023-06-15document_EF298_Jun_15.zipzip 1460b2ce91f6142bcec3bb6f8852eaf8652a022ac34b1481134fa020cd586b24Virustotal results 6.45% Quakbot
2023-06-15document_BD348_Jun_15.zipzip f8d550697f06844c92e85660a6cad2958535ac32ed6cea75ae9a064efc83a305n/a Quakbot
2023-06-15PuKPZoA3jGqbzy.jsjs 324b1badff9a5c2fc50fefc7606337055a94d914ec26147fd0d524d6b8badf76n/a Quakbot
2023-06-154rdaeBMAwjT4.jsjs 685620f934b66e6e8f1224160dfeed2263ae42e96742b5a1a5e04572347c7c70n/a Quakbot
2023-06-15RCPvGbv76hvMjQ.jsjs d1e131e24dfc38ea0883c94ff86e7ede73c5db56257b802a33fa3c639b0e7e1eVirustotal results 20.34% Quakbot
2023-06-154jWFmFFBJ9Nz5.jsjs adbd39a068fed7567f68e6fe741f65352efc5d631ccc48c4f4c1f9ebb01dff4bVirustotal results 3.39% Quakbot
2023-06-14wTIaZuCqpmr49.jsjs b943b8fe4f34bc8449bc8a72e74e15539ce20e9347ab6a391610ba83553453f0n/a Quakbot
2023-06-14MkRgOI9rr2J0dB.jsjs 8531318e0e87fb75bd117adf1088cade8597e9b6c5f99a15e8d0f7b93179a747Virustotal results 15.25% Quakbot
2023-06-14n0WspYxkdDbD.jsjs 0f9701757e68ec0d0ac7c031be3bfaf5e73f8c76065bde54310bde8829427a83n/a Quakbot
2023-06-14docu_EF925_Jun_14.zipzip 10e566dcc281e6b991c1793ec7bb7fcf5340ff7c607fbc94780502a1567b8bc0n/a Quakbot
2023-06-14ZOoLAEZKkybj.jsjs 905af047345addcf40ced0d92bc5164fad2cc99dead0c067e5b5f091d2e9c24dVirustotal results 0.00%Quakbot
2023-06-14UKwopBmP7q19nX.jsjs b7d3d9170b9c0608e3fdd7305a783e833cb0797041f5c18547800b53269c7a3aVirustotal results 15.25%Quakbot