URLhaus Database

You are currently viewing the URLhaus database entry for https://nokri4all.com/lua/darpirtuoaio which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2320553
URL: https://nokri4all.com/lua/darpirtuoaio
URL Status:Offline
Host: nokri4all.com
Date added:2022-09-28 18:07:13 UTC
Last online:2022-10-10 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 18:08:10 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:12 days, 0 hours, 31 minutes Bad (down since 2022-10-10 18:39:51 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-04Co2768557681.zipzip acf816796ae2e5df59f7255320cb5ca90b31f8a306226d269984b90b14528808Virustotal results 3.28% 
2022-10-03C4029125045.zipzip 4a83cf2e772a4a11fbcb1ae439208666b27cd48c5ae5ea6766b4ce2dca0e100cVirustotal results 3.23% 
2022-09-30Post2610074945.zipzip 2be0f41af6567d02a1f54045e571811753343e855e51250044513d46d8f09fb7n/a 
2022-09-29Gall3583109565.zipzip 65a0904b43124470c5268cf89bd164f23692e9730aa15233fca58446fb06ee6dVirustotal results 3.17% 
2022-09-29GgPnDIQtinkJHYTnIO.zipunknown 3700729a69f774df012e556ee946a4ed7c910e3884e12a09ecd48e24399769cdn/a 
2022-09-28xPnzT.zipunknown cc0aa68c2f0d2f6321cd19326abe8ac1f6756161de52b004969e3f3d5e42dd39n/a 
2022-09-28czsWlRLKLlfc.zipunknown 385f8e73831152e0ec9e1ca58fdc5a18778d47e750724a6cdbdccf338722ed73n/a