URLhaus Database

You are currently viewing the URLhaus database entry for https://carpetwagon.com/esa/ndeons which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2317864
URL: https://carpetwagon.com/esa/ndeons
URL Status:Offline
Host: carpetwagon.com
Date added:2022-09-28 17:45:26 UTC
Last online:2022-11-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-29 06:27:08 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 months, 1 days, 2 hours, 5 minutes Bad (down since 2022-11-29 08:33:00 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-19CgBadkCFc.zipunknown 5942ad5fec2554bacca872d04eab1e2a95320d03eedd1e75d56be45e7e2803a7n/a 
2022-10-25HOqHTiyRcSYdzzQFJ.zipunknown 1f9e1f744d7d58ba0013878246917e6128b98a471226bea5482b6055c9870523n/a 
2022-10-21uTrvWgwaslXPWBGrxX.zipunknown f00c9803a651c4927daaa5a5037f7a469d3a04cea360341d747b08bb0ea4c8e1n/a 
2022-10-15bdpbVtNiwW.zipunknown 15176933b39a9c297d4ad71e01863c1a166817a2ad0f3c9f3ce86f7911baaf0fn/a 
2022-10-13rFzy.zipunknown 2d6bdb5ff666a8f55de3ca57db5174b372af9268dd9082a787825c73d6610b4fn/a 
2022-10-04CA3761510407.zipzip a21d678637f598c2038281cd0b3122a3e182a92e76c4373333537266d6f16394Virustotal results 6.35% 
2022-09-30Card1557756433.zipzip 9dc0710738ca161a4e629a2c34af70dff3ad136f0de32e1886a6261c0e59419en/a 
2022-09-30P3000041150.zipzip b9a1328f3107582e58d4fef064f2d3998b658ccc513f9e98a513f5606400d9ben/aQuakbot
2022-09-29Gall3868781033.zipzip b7c0669b710a08d6c9f9dee762dcbb689f10081fe79a4a346c00a34bc5c1dea3Virustotal results 3.23% 
2022-09-29Gall4148241443.zipzip 3275851c1d086ad1d466a8159cff422cf9e04bf28c92d01e25a7a165b8650828Virustotal results 1.59%