URLhaus Database

You are currently viewing the URLhaus database entry for https://jokersbusiness.com/su/offerZani which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2369017
URL: https://jokersbusiness.com/su/offerZani
URL Status:Offline
Host: jokersbusiness.com
Date added:2022-10-13 15:44:33 UTC
Last online:2022-11-28 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-10-17 00:18:10 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:1 month, 12 days, 14 hours, 52 minutes Bad (down since 2022-11-28 15:10:41 UTC)
Tags:BB01 BNO87 iso Qakbot link qbot link Quakbot link TR zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-19G820641201.zipzip 6a0eff54edf6ecdf610c985cf01d78313d93a540a8f25ca718d953f3efa6c1cdn/a 
2022-11-13k8.zipzip 1f90620310fe61c205633fe3f347edd7ba1b142c84c78a113dd644bb4272ea49Virustotal results 3.12% 
2022-11-10i5.zipzip 5d681ec2d980a531c8ad61e6593160803dbbf60b53ebc5e0f2aad218f5391cffVirustotal results 1.56% 
2022-10-25Contr658.zipzip e323ddf906afd94772e55e2139f881db21a2b0aad20c549a92f6220e3efba32dVirustotal results 1.56% 
2022-10-17D855058085.zipzip 54591a68bc54bf98bdc126efcc2693242f73257a6660ff9665d9d508bb26d8b9Virustotal results 3.12%