URLhaus Database

You are currently viewing the URLhaus database entry for https://natwalliance.com/ixme/moutsaltpouituv which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2320663
URL: https://natwalliance.com/ixme/moutsaltpouituv
URL Status:Offline
Host: natwalliance.com
Date added:2022-09-28 18:07:42 UTC
Last online:2022-10-11 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 23:14:08 UTC to abuse{at}colocrossing[dot]com)
Takedown time:12 days, 21 hours, 52 minutes Bad (down since 2022-10-11 21:06:25 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-08R1597973564.zipzip 8cdb61a3816a7863d2e0f15b69bd9441d0cf95866b72b92a67afa32e9ac396a0Virustotal results 47.69% Quakbot
2022-10-04C1586513701.zipzip fe8eafd15eb657e9330a1781b07b2539f74849f614a0e60aeb8e030c9c141912n/a 
2022-10-01C3322213197.zipzip ce02af62274b3a226acbf52f15adc5144c5eb2ae009174c84168e9bb3f048898Virustotal results 3.23% 
2022-09-30utaEt2205637393.zipzip b9a1328f3107582e58d4fef064f2d3998b658ccc513f9e98a513f5606400d9ben/aQuakbot
2022-09-29G40292659.zipzip 466b66315bf1fa84c9538469caada0735f9fceab44ab1b47aea1250f0b77fd95n/a 
2022-09-29G385787829.zipzip 0ad6192b4105c85c439fbc015b2e26d9ef3902995d4d90bbf0e4212a9d6abd94Virustotal results 3.17% 
2022-09-28G1251160542.zipzip e05947f4870002d493a27af3145204bae9eb68a23c1d54ffd56b705791737301n/a