URLhaus Database

You are currently viewing the URLhaus database entry for https://codixgambia.com/sid/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660064
URL: https://codixgambia.com/sid/
URL Status:Offline
Host: codixgambia.com
Date added:2023-06-14 09:02:27 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:05:08 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 7 hours, 10 minutes Poor (down since 2023-06-15 16:16:04 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BC260_Jun_15.zipzip ba5a511269cdbf860978c0ab23edf095d7748e93f88a5b62b67e2b47ed23e180n/a Quakbot
2023-06-15document_EB645_Jun_15.zipzip 858c02d15feb4edcbc1d08fc2781c7252d398cb6042533d1e8bf433a50ee77d0n/a Quakbot
2023-06-15hkPwh2mvo3Bxk.jsjs f426031c99dec67fc3de1b4c297db3d11ee9c94515275672588b33e915f9291an/a Quakbot
2023-06-15CqwN2oVxq95T7F.jsjs 089f84455149ba4a51a6963ff682d1bb87c996a09770f44246f98ffff8d8346an/a Quakbot
2023-06-1523DjEfAPuSciYq.jsjs 993dc734b9e5b5d49b5289df98acd4829aae53b6aa73d994c2a150ba71392784Virustotal results 0.00% Quakbot
2023-06-15bDcSTdIufKrIh.jsjs 14ff31d5b89b5579a80be5de1f01e7360331647c4d7cc9b2cae9868812cd5effn/a Quakbot
2023-06-14wmsBOhzhygvUw.jsjs b78b54f956b95a726a95ec2bdfb3e99a516589b557df5dcc2dc5379484114d54Virustotal results 0.00% Quakbot
2023-06-14nv2flKP6j7SM.jsjs d8d6784a28a1d89fc7b6281ec11967dda1e5b8073fbce2a951406512addfca3dn/a Quakbot
2023-06-14DTK0NXvfTu1B.jsjs 747cb3c646fce80299108fe0b2a6be686f98e59cb3688e6bdcf95456cfe7f286n/a Quakbot
2023-06-14bobSuccDWQwXo.jsjs 7d62555b7556b1b9005b72497f471b0f4519e9d459cc69a9f3eea3ccb3df175cVirustotal results 5.08%
2023-06-14plNITUAExbTg.jsjs 70bcc77132ab2141c18165d1b8238199d381d58e4eb5096871d34079688ad75cVirustotal results 0.00% Quakbot
2023-06-14WnDK3vYAwLWFS.jsjs ce325aa2f2fa00c9f66f9f6e16ca0c15dde3c71774e25fe0d2fa98377e4fa907Virustotal results 1.69% Quakbot