URLhaus Database

You are currently viewing the URLhaus database entry for https://civilwarhomestead.com/idii/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660868
URL: https://civilwarhomestead.com/idii/?1
URL Status:Offline
Host: civilwarhomestead.com
Date added:2023-06-14 16:56:28 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-15 00:36:07 UTC to abuse{at}hostgator[dot]com)
Takedown time:15 hours, 36 minutes Good (down since 2023-06-15 16:12:54 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_EB475_Jun_15.zipzip 0402adc811c08499f0872416e1244b422e2bdebd1d53690d7dac58b40acdf137Virustotal results 6.45% Quakbot
2023-06-15document_AB290_Jun_15.zipzip 7c9c625b781be20e0528316644d6fda0db54868931492fd5869114bc344f1a6dn/a Quakbot
2023-06-15NFFs4atcfHIe.jsjs 37f3a7a16c9738d381bb2305cfdc07f2e1517568c5aefc96f5bc0a88e3c381b6Virustotal results 15.25% Quakbot
2023-06-15YPSlqbBlgacyma.jsjs 6508e1a287dc5cc3c989da63ccaa7b16553f56e7d8deefb2d3b690aa222673aen/a Quakbot
2023-06-15LsKin2DGHSAJ.jsjs 52f86da4a697d01dd8135de150adc8471479dd83eb1b1ff0b3d472585618d84fn/a Quakbot
2023-06-15dW4W2833gkECeG.jsjs ddb59a1215e9cd8e50a679cf23fe12942bbce86d90fe0a2c21a8fcb61ae445ffVirustotal results 13.56% Quakbot
2023-06-15qhCLh8LyzPOnH.jsjs fcb0a1ad70aac7965ca82f7b7da8beccfd6503ffc8ea640f6cfc72edf939267dVirustotal results 0.00% Quakbot