URLhaus Database

You are currently viewing the URLhaus database entry for http://werkplaats1.okker.nl/jiejgtgde/44266.4809465278.dat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1060704
URL: http://werkplaats1.okker.nl/jiejgtgde/44266.4809465278.dat
URL Status:Offline
Host: werkplaats1.okker.nl
Date added:2021-03-11 06:11:09 UTC
Last online:2021-03-11 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: papa_anniekey
Abuse complaint sent (?): Yes (2021-03-11 06:12:05 UTC to abuse{at}yourhosting[dot]nl)
Takedown time:2 hours, 29 minutes Good (down since 2021-03-11 08:41:55 UTC)
Tags:qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-1144266.4809465278.datdll bf004841585af7964a8c6533aff6aec0cbb6142f4ae4f24fb3f9d2538ea44168n/a Quakbot
2021-03-1144266.4809465278.datdll 0a5dbcc0f2586e4b734ee55c3cbe07ac2ddd0b7ce67a34cd1ef9072747e0dfa0n/a Quakbot
2021-03-1144266.4809465278.datdll 32a608446d3e5116814291feec0ee676320e9308e62acf9ff2b7d30cf9d2b8aan/a Quakbot
2021-03-1144266.4809465278.datdll b10c6588eeeadb60d7a6602e49cfb74105fb28f2fe2d55b5e6f9728f76c3324cn/a Quakbot
2021-03-1144266.4809465278.datdll 10c9da97e08f1f0b3ae1dc34f9f3433489bfe55bcb1952f558c272e6f54bfd97n/a Quakbot
2021-03-1144266.4809465278.datdll 2c0df18a2011dc994777ee6525ba6748137fe44aecbb19b226c665ed2d88b41dn/a Quakbot
2021-03-1144266.4809465278.datdll 01714f35a7f43a1993b542d768e69756598769c32a56550ceadc60e7c3c97835n/a Quakbot