URLhaus Database

You are currently viewing the URLhaus database entry for https://globalhse.org/entu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660319
URL: https://globalhse.org/entu/?1
URL Status:Offline
Host: globalhse.org
Date added:2023-06-14 12:32:40 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100133168 created on 2023-06-14 12:33:10 UTC)
Takedown time:1 day, 4 hours, 31 minutes Poor (down since 2023-06-15 17:04:42 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_FE263_Jun_15.zipzip e21e9ccf9b2f980a2c724cab2a4a9ff4cca6be9a117e18ebc3be54fc5011f999Virustotal results 6.45% Quakbot
2023-06-15document_DB032_Jun_15.zipzip 7c4b60f4da6ca1854167a630b36f73cce9139c31e26f524e6d5b4022dc23d952Virustotal results 6.45% 
2023-06-15document_BD260_Jun_15.zipzip ef14667b3ce40ee178f1a9b3f6f3fb71ce20bd96b5483dde83acc27deb66291bn/a Quakbot
2023-06-15document_AE519_Jun_15.zipzip 25c0fb7cdb7acf37c84d84318a4f598f197b09519279275efacb54570f139ee7n/a Quakbot
2023-06-15BSRJJtD3cKyofb.jsjs 7d298e6538b80be42fa8321f1709f1c0b138517f87e2156f870caa2c44cf412bVirustotal results 20.34% Quakbot
2023-06-152KYI5RoxUmN3c.jsjs 754a5f22e16b736659604105224d4333a57004d4c6f4c4aaaa5f6629931a2b27n/a 
2023-06-15CcmD4UEm4W58RE.jsjs eff02f7320bdf1d2effc76da9f8143162b37e632459d366bcbed8863208cb4a3Virustotal results 0.00% Quakbot
2023-06-159gRL58HTi0i2.jsjs 87f498b6b1cc9d8a87883ac481530d47ed781cef7c7c9d9faaed126550877676Virustotal results 15.25% Quakbot
2023-06-141CXyIa0EZsbP.jsjs a242b467fddca6e5a80b07ff3029b6df2631dc8a84114ffe59643a8c43e872cfn/a Quakbot
2023-06-14NdLEIemeGWGeq.jsjs e287b94ccd12dc41e98edff7ade74e1659809fb9ce3898bbc6abe7ad3579f966n/a Quakbot
2023-06-14docu_EC230_Jun_14.zipzip 2e3f3e13937cc2e623db18df77e5fd709db78e65fd38de968113df58abd14133n/a