URLhaus Database

You are currently viewing the URLhaus database entry for https://balgocburada.com/ar/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2667490
URL: https://balgocburada.com/ar/?1
URL Status:Offline
Host: balgocburada.com
Date added:2023-06-20 11:58:58 UTC
Last online:2023-06-22 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-20 13:45:10 UTC to abuse{at}ni[dot]net[dot]tr)
Takedown time:2 days, 8 hours, 6 minutes Poor (down since 2023-06-22 21:51:15 UTC)
Tags:BB33 geofenced js Qakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-22Nwtxv.jsjs f9255e8cc8dd2b7d6282a5882d372b8e813de569add3bc56c53d85502a9a4aa9Virustotal results 3.39% 
2023-06-22Fct.jsjs 4d211e7562a20126f32d9903003be31f2f13d850cfb364007edd741474679aadVirustotal results 22.41% 
2023-06-22Rxgh.jsjs f55b5a286f82f6a118d5502fa3c84ebe913fb9250fcb458af1053121e5a20831Virustotal results 5.36% 
2023-06-22Fqhqu.jsjs bcf7aa9287bdce308f0ea598b168614fd7d63093f30ea8f80ee3200478dc1e59Virustotal results 1.69% 
2023-06-22Vkuha.jsjs 023b42dddd5c581a3d1e9b5d655422432ed675c2081e90de2955ca675a9128caVirustotal results 1.69% 
2023-06-22Lkaqp.jsjs a906060d87ec0949935ebb2989b44ca49ba581c30730d876958613bd487d4496Virustotal results 5.08% 
2023-06-22Eqym.jsjs e2f7732b6f55437c9c35fa3940680b7f08494441146c38f9e0b570ce32b26fc8Virustotal results 6.78% 
2023-06-22Qvmc.jsjs 9281f6ed5b6ab7a9abc25d1b3b7a8d56629c525f8c6a6384215c6f9367c8c724Virustotal results 5.08% 
2023-06-22Outah.jsjs 5ff41435840c3a8e45b7c54977363a8f557a65d16f6c340ac449c2c7b8f334d2Virustotal results 3.39% 
2023-06-22Vav.jsjs e69ed21d343481cd4a7f93b4140fe27fafc44c7de8f3000b2f3fbc027042a431Virustotal results 1.69% 
2023-06-22Hte.jsjs be5c406f1206116dc548b8edd9772e47fe17aef15646dbf0558af6fc9e36f5f4Virustotal results 5.08% 
2023-06-22Byoi.jsjs 61db153526fb9a9190e6b6609a7794b1409742d021b2c11a2ce07bb89173542fVirustotal results 5.36% 
2023-06-22Kpnr.jsjs 43a39800fc12bab54014bbedd5eff5adf55860c966afa0f5c89469c8331ff4aaVirustotal results 1.69% 
2023-06-22Pxt.jsjs 058155c461c3d5835509ac484c691c9174b6eb72bb92683138e04b437f6dbc5cVirustotal results 5.08% 
2023-06-22Tkfbl.jsjs 6ce9fa360d9f8ad29d803117080fed8c4885f6ff757291adac5b54746d540a1bVirustotal results 1.69% 
2023-06-22Uhygz.jsjs c6377934874cfa84351b903ce1274fa9423eb4441f42625127c370531f75724dVirustotal results 3.85% 
2023-06-22Fox.jsjs 218bc897cce017961adef5ddc4f772f1bd935584e923750ba6b7107be460ebd5Virustotal results 5.08% 
2023-06-22Haj.jsjs ea146021dd479c8f16e40b48385f9e267c5ea633529e2afaebdd439d564277c1Virustotal results 1.69% 
2023-06-22Maq.jsjs 481eb99e35a2fc2346a3d2274cc9509c7476d64b1228254557b485601b6df10fVirustotal results 1.69% 
2023-06-22Vp.jsjs 1cb97013329c0cb612a27111ae7646cb8e44d6688383bacb52ef6e7b64c9d1f1Virustotal results 5.08% 
2023-06-22Bpb.jsjs af47496bed0157a418f135566be948ddd387f6040b626f559762b7d61d0237f1n/a 
2023-06-21Rm.jsjs 48ddd768ae008b7057f89420246398e505a63f2ff3386f7de1bbced1ada0acf4n/a 
2023-06-21Lhby.jsjs f60f2fdcb45d358c105bfa46f0ac17bed42d35b479ebd0af065d6a7ea9cad01en/a 
2023-06-21Ae.jsjs 4ab4aa235d6279224bd54c236b5663ce7244039fee0e542066baf217d457c7ebn/a 
2023-06-21Bndjk.jsjs 9a72aef66b0b622579f02830bdabb405c4ca7c31ad9401e1916b4298ceebf52en/a 
2023-06-20Tg.jsjs fc4ab152a011b5d3a85fa109dfac301e1fad2b510272d743d28f95ba08b27679n/a