URLhaus Database

You are currently viewing the URLhaus database entry for https://essay-ninja.com/octi/utrtriaapu which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2318679
URL: https://essay-ninja.com/octi/utrtriaapu
URL Status:Offline
Host: essay-ninja.com
Date added:2022-09-28 17:53:08 UTC
Last online:2022-10-22 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 17:54:15 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:23 days, 19 hours, 31 minutes Bad (down since 2022-10-22 13:25:24 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-15ISzg.zipunknown 875fb908792e0a402fd503c5c87ecbea20739f041b4f7d460f838a084973c30cn/a 
2022-10-12Of2275242757.zipzip bc3e760feea590e93c8338f3d283da970bae55ad16060366e1f12dfcbe299e1eVirustotal results 1.61% 
2022-10-09Co2899639009.zipzip b803a6e9bf369f2dd83b0901c1a18a076ed2906a1e7116146f5b28f5ef2359f0Virustotal results 50.00% Quakbot
2022-10-05R2406251335.zipzip 386538bf14b8ee6bc15f1e28e4cfa1b3c62ada98cd0455da3126a7c39af3c206n/a Quakbot
2022-10-01nptrteouaoaseCqumr499551691.zipzip 32e3c0eb1632a4a8ec2cca2ea174e735d40736a659634355a0db66b9cd8d0c1bVirustotal results 3.23% 
2022-09-30P3863960903.zipzip c4774a48c2d70b80203c70e7cbf3b3d27fea869294f936e6d484ae43c5824981Virustotal results 3.17% 
2022-09-30xBaEoRlHI.zipunknown 51b9d26d9cd9b8ee7fdcaa1e66fbf680a32bc9f31f104292934e35923757fe04n/a 
2022-09-29CDjTHMybnoFSaGdvp.zipunknown b9f0daef3b17de74cba3193639830ed1d7d8c47d01acdd342c89da1f1023b8e6n/a 
2022-09-29LSqoEsmvbscXvJiscQ.zipunknown e48f27ff28dabcc0ba33c0b72cd16c3a9135338258b3c89fe58e1ef4cfbae1cdn/a 
2022-09-28tbnqYCOwdxGDqCAZC.zipunknown 85943fbc83d1e31b510190d35b97e1e6825fd1e143bca6e04eb268b33e6fb676n/a