URLhaus Database

You are currently viewing the URLhaus database entry for https://sumeetgroup.com/on/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660261
URL: https://sumeetgroup.com/on/?1
URL Status:Offline
Host: sumeetgroup.com
Date added:2023-06-14 12:32:26 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100133164 created on 2023-06-14 12:33:05 UTC)
Takedown time:1 day, 5 hours, 7 minutes Poor (down since 2023-06-15 17:40:44 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BD190_Jun_15.zipzip 8cd253070aa7e2d56b2467a8ce0fbfe4b0e2127b397b9d626c4495ffb733a84cVirustotal results 8.06% Quakbot
2023-06-15document_DB470_Jun_15.zipzip 30668373215a3f73514f170b0a85fcf829a9b5689b8aa552cbf515b0e1a20ff0Virustotal results 6.45% Quakbot
2023-06-15document_EA174_Jun_15.zipzip 8bf8aeecd1801fa135021ce4ff7b0114258fb6f17d7a2df07eb364e80bce6ff8n/a Quakbot
2023-06-15IMRBv424MHDWLy.jsjs 439ef2597ef366186f671f4f10c8072d99fbdad2816f146eb0a0619e7dafa799Virustotal results 13.56% Quakbot
2023-06-15rhVwdFRdulfZZF.jsjs e30dd29e5bd9f6e227fe3a973dc5235664b05193ba16b1e1df3f2a023e19dc40n/a Quakbot
2023-06-15ffOcpHy0xI2R.jsjs 24d547ea53a971c9f653fc732a977d5718dba1e798f5b0f4561fcc137e0e1a5dn/a 
2023-06-15MCClx6TKh6vf.jsjs 9bab8995878492fd4238680e2625f7d8cdd0ecf7eb1e0794f249ac934df6dc7eVirustotal results 0.00% Quakbot
2023-06-15fs5yNHgdMHJyzS.jsjs df3951d408f334328c9954906ef8c22cddb780c5a86594bbe7e06449e10de354Virustotal results 15.25% Quakbot
2023-06-14hYEXCVfJEl9pnr.jsjs 68d8f77631c3a75b154342048319cfef746d0292239d7666df3e1a98bf58348fn/a Quakbot
2023-06-14dCJaHI3nz83l.jsjs c86b0d6aca6e60abf1330a5a34d784e00bc6b74e556752ae37fa49a7d96ef49fVirustotal results 15.25% Quakbot
2023-06-14docu_DA310_Jun_14.zipzip bb420e0f70235e1ffe6c6f938a31191eae8e01f8e51e0aaa12389a6ee2aa6db1n/a