URLhaus Database

You are currently viewing the URLhaus database entry for https://nokri4all.com/lua/aufigtte which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2320594
URL: https://nokri4all.com/lua/aufigtte
URL Status:Offline
Host: nokri4all.com
Date added:2022-09-28 18:07:24 UTC
Last online:2022-10-10 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 18:08:10 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:11 days, 16 hours, 54 minutes Bad (down since 2022-10-10 11:03:05 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-03qUsQtJuOyXLnMic.zipunknown d5c8dbafe69e93a502dfa5fae153a0812ec3eaf155e8143fe0c6d6b1a3b95fean/a 
2022-09-30C2378234536.zipzip 2c9bb836bc7319035c73bcda1f8d332085db07fdcc137cb3d1d26f96aa89d7d3n/a 
2022-09-29G2138488535.zipzip 8af521d02fca01e28ea8cc8e470c5a017b706c2259348b69d7e7a18d16eed465Virustotal results 1.59% 
2022-09-29WCtqFh.zipunknown 2801e8782bf8ba8a301305799a5ef1585ad59970e94e564ec36f7ef06f594b49n/a 
2022-09-28CbXPi.zipunknown d1f914b7de7770554f84d7e1c310ad2a9ed5e4b10752a970a424f2dbbe89861dn/a