URLhaus Database

You are currently viewing the URLhaus database entry for https://essay-ninja.com/octi/utsruqneinmecoa which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2318757
URL: https://essay-ninja.com/octi/utsruqneinmecoa
URL Status:Offline
Host: essay-ninja.com
Date added:2022-09-28 17:53:22 UTC
Last online:2022-10-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 17:54:15 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:24 days, 19 hours, 10 minutes Bad (down since 2022-10-23 13:04:57 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-19mxvggy.zipunknown a644c6a6ca95564f04c59f5cfb96052e2a2159177c8c60734ea9f3620e535f6en/a 
2022-10-12nMCk.zipunknown e8751279b54c3995180a5812c48978ea90e029302861777615dd5c37968e7746n/a 
2022-10-06R3003106413.zipzip 6049a55a877aba3cf634583b49d6e5d35049104d9c640f9471b5687fff94e882Virustotal results 21.21% Quakbot
2022-09-30CA2496883114.zipzip 2412dede462c28ebd7252eccf495207392ec9f8f5efac3c18a465c1168960ab0Virustotal results 3.17% 
2022-09-30Gall4220220106.zipzip 7c780c52882596cd1fd7c37b7369a9aeafb55887654a2195d26097f3d7beff54Virustotal results 3.17% 
2022-09-29eGPRjVpALWi.zipunknown cd72ac18b9a77bd10a58e9491e607b0b96506f6e584d5281da56ff8de73294b9n/a 
2022-09-29cVueoe.zipunknown b41bb1e21ffc14e6ecf8e7022be07619643dc968fca05db6a988849d20b635cen/a 
2022-09-28oEDtBXTxWyvrDNAdjz.zipunknown ba447fb4f940073a1bbfbdf5731809195a772703da164475d929db557e95a7c9n/a