URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: nosah.one
Domain registrar:Namecheap -
Domain registration date:2021-07-28 01:28:23 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2023-06-13 17:52:25 UTC
Total malware sites :1
A record(s) observed :10

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2023-07-28 07:45:42 199.59.243.224Not listedAS16509 AMAZON-02- USno
2023-08-12 17:18:11 172.232.4.89hickory05.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2023-08-11 21:15:07 172.232.30.16hickory04.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2023-07-31 17:49:41 172.233.218.191hickory02.parklogic.comNot listedAS63949 AKAMAI-LINODE-AP- USno
2023-07-28 04:28:44 13.248.148.254aba1c1ff9d2ec5376.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2023-07-28 04:28:44 76.223.26.96aba1c1ff9d2ec5376.awsglobalaccelerator.comNot listedAS16509 AMAZON-02- USno
2023-06-13 17:52:29 188.114.96.3SBL690066AS13335 CLOUDFLARENETn/ano
2023-06-13 17:52:29 188.114.97.3Not listedAS13335 CLOUDFLARENETn/ano
2023-06-14 02:48:41 104.21.29.196Not listedAS13335 CLOUDFLARENETn/ano
2023-06-14 02:48:47 172.67.149.186Not listedAS13335 CLOUDFLARENETn/ano

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2023-06-13 17:52:29https://nosah.one/aiai/OfflineBB32 geofenced js Qakbot ext Quakbot ext USA Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2023-06-15 14:56:30db93500e44a2684e71d044699c1c5270916723e212ccdb4957d1eacfb41864a8zip Quakbot
2023-06-15 13:56:464215d40540cb530490e0b70feec1d97a1c37e03b8e816f2e3b0f815f1eb963aczip Quakbot
2023-06-15 13:05:44ea3fd78e2934af8a995496463374cdef10b0fe052309e5370f8ba7b638b1eb34js Quakbot
2023-06-15 12:18:19b12782232c7f6fe1960b872c3beb4e4fb8be6e8e6484a3dababb12e4dae59884js Quakbot
2023-06-15 10:09:077edbc8d2106e350a859cae6e9e0de259c790a158e43ee255fb76be64e85d9724js Quakbot
2023-06-15 08:43:358b69b2a765d237d79ed128ec38a4e471222e43c528689953c7029423680bd209js  
2023-06-15 03:10:483543fbf5b817372eb12b4db3de2f415cd4a717edf80d0fad36536e3f7c0dc6c8js Quakbot
2023-06-14 14:49:51e95bf20a416f547272d525136fdee112307bd8b1bc6036d558a0bb2d97c113f7js Quakbot
2023-06-14 13:32:464a703b68f597ee967183e609f39984ea9198493ebd535d069f8ab458d90b29f9js Quakbot
2023-06-14 12:34:05f47c875c7ae2f065c1ef73ea596ba1f3d9b876474e5b6fc7e6b91819f11ba990zip  
2023-06-14 11:40:39f13ef56e5c6b044131aeb5b7c669639354624bf367338c1b166d55177fff0390zip Quakbot
2023-06-14 10:55:11efd9d13ad982dddd3f52e753dbc6306173d53ffec9664190df0b5fa099af0966js Quakbot
2023-06-14 08:40:478a2dd98512402598992549ff209edc910eca09454686b9c0502d7e883e064509js Quakbot
2023-06-14 08:23:4933cd588c4ebfa4a6ba76143306d7e61cda9250ddba43c215bd05c71dcbe42e3djs Quakbot
2023-06-14 06:53:201931cee49f7e8c236682655e3d81dd703ea9e3566bd3dce49a504331d2d747ffjs Quakbot
2023-06-14 05:02:1855d3492acd4da04075013f5fba3ab7e4679f3dec7f671a3f0ae21850e76f1ea3js Quakbot
2023-06-14 04:31:266c4e5c92a7cc22610d2799193e299e3699e3aba8c77caa8668c9ac83cf79f8d9js  
2023-06-14 03:18:1587c2c690b9a4ccd266848d48dcddec5f21472f30e1684066638c44e7f287e51fjsQuakbot
2023-06-14 02:48:359efdf759a7bfbb48310e66c322b48ff213edac8fbccfa22e67e736ceaa0a79ddjsQuakbot
2023-06-14 01:06:1410fc5f940ccf6de1541568b1e647577528c326344c22363ac7fb2f97e964afd3js  
2023-06-14 00:00:187229a67d0b9de46809d0fbde394a198b54a9d449a20c2ebe7d26f7e695b881e3js Quakbot
2023-06-13 23:01:37dc380c6947c5f8de2586ab7baf30b36b6a9426932323cb2096af2c5f4e2c344djsQuakbot
2023-06-13 21:43:01524df894244a701b9825ef6f279a4ba64292f219614dad255858ccd503a896b3js Quakbot
2023-06-13 20:37:38e918e17a0a639c0f284a76059249a8398b71eb09bb54e4409fe6ae526a332431jsQuakbot
2023-06-13 19:07:436966078593074ed205090b55924c213c5d93a9e4a3c798cab4bebf084ac20161js Quakbot
2023-06-13 17:52:292d43a56a449ddc34e368a2de42a57af3fe0a426065e6dd433625d4745b1a6d67js Quakbot