URLhaus Database

You are currently viewing the URLhaus database entry for https://varow.com.pk/eeso/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660060
URL: https://varow.com.pk/eeso/
URL Status:Offline
Host: varow.com.pk
Date added:2023-06-14 09:02:26 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:05:03 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 6 hours, 58 minutes Poor (down since 2023-06-15 16:03:14 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_DA478_Jun_15.zipzip 39f523c9f9eb461e5c640837b9f3efa16fe66aa44ce7b7fea772c01bb05044c9Virustotal results 6.67% 
2023-06-15document_CE013_Jun_15.zipzip 26974a8110e5749eff5f1b4dc8a1edf3869f649c55e5b7029e74b149a59d09edn/a Quakbot
2023-06-15SiZB8ohF1zd4.jsjs 3ebca31e19149416bd4cb296a1b6f77f4e8e24f5ccc74227534a52d770653964Virustotal results 16.95% Quakbot
2023-06-1533yUPdXaL9iUCk.jsjs ed7419179cbe1d9a13236cde8d4203ef3840e085231e61c72dd87f855d1dfc65n/a Quakbot
2023-06-15paqZA0WJm2Es.jsjs fcfbe6da11b1b2f733085ef6f63abaa07aef50b8f899fb5ae9a61e06645f9212Virustotal results 16.95% Quakbot
2023-06-15r5Lp9sJwcheY.jsjs 8f432e96bc04425d0082b2fa693833d8d58540e76d7d6f402e727a932d7cbc48Virustotal results 0.00% Quakbot
2023-06-154kLYnSYjkaj6G.jsjs 82313ade9759830bef7315f3c769957810ce78654f47e8fe118a7c25de2bdb3fVirustotal results 0.00% Quakbot
2023-06-14brhTDeo9z47b.jsjs 4f1faac15ebf8462927340a8ac5789dc4c62699df9d5393b2b73741c5b024204n/a Quakbot
2023-06-14c3nki7epikkhB.jsjs ba5e0ae2ae06c79c15d4250c3e987d47dd5696736ad2d7e9300970159aa71abbn/a Quakbot
2023-06-14docu_AC706_Jun_14.zipzip 83fafeaa744c8dd926bcc0374ce0d13960f9ecbfb5947ed3f62a918304e520ebn/a Quakbot
2023-06-14MwwW7tTYf5j9r.jsjs 539cc769b7c26c392efde9f1b3b55419c4bb839db80aa01d2090c6ca2882d7c0Virustotal results 3.39% Quakbot
2023-06-14WQJ5Ev1oJMmtm.jsjs 5c666d42ddbf63e7b6e5256e360b9b627a8f6383db3b040c888ed662123ca8cfVirustotal results 0.00%Quakbot