URLhaus Database

You are currently viewing the URLhaus database entry for https://bisff.in/aue/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660741
URL: https://bisff.in/aue/?1
URL Status:Offline
Host: bisff.in
Date added:2023-06-14 16:56:12 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-15 00:13:05 UTC to abuse{at}deft[dot]com)
Takedown time:16 hours, 8 minutes Good (down since 2023-06-15 16:21:47 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AF416_Jun_15.zipzip a5419a1e511c878cea25243c4a59452111069c4fcc102005921d550703630f9bVirustotal results 6.45% Quakbot
2023-06-15document_AD278_Jun_15.zipzip a68301645409a864428d308f5f5924cc06f9997915cb057483429613f091409an/a Quakbot
2023-06-15document_CD854_Jun_15.zipzip 5f9040ae6827e43a7ea450dc219b2531254f03418ed17fa3ba6d56953537b948n/a Quakbot
2023-06-155UnLQEL2uwJjc.jsjs adf944c592b6f4738467861010f5e394a3e8d9ad267eafc217ffc31623446f93n/a Quakbot
2023-06-15LP54JmBlQ5In.jsjs 81cb03e448edb58b4c08142742461836939ed9e6bbdf8f681e91e7896524a63cn/a 
2023-06-152DaaxOKctyjx0.jsjs c020b80a4b247dc41cb9f9dae71a6a597c42a0388eb6eb730bc3c0b16e03e621Virustotal results 16.95% Quakbot
2023-06-15hpupQjePl3982.jsjs e381e9e8ca6334986a8b1c0a1f03631f020966c6cc74a7b7dc218fb934362cacVirustotal results 0.00% Quakbot
2023-06-15H78bmn1XcxMkgq.jsjs b5f759f8bef08022e7cad6842c5e3e806163012da96541146d5c8276e1765c6cVirustotal results 0.00% Quakbot