URLhaus Database

You are currently viewing the URLhaus database entry for https://lipsumtechnologies.com/nsmi/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633857
URL: https://lipsumtechnologies.com/nsmi/?1
URL Status:Offline
Host: lipsumtechnologies.com
Date added:2023-05-16 13:14:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:15:35 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 8 hours, 19 minutes Poor (down since 2023-05-18 21:35:33 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xbxqz.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Lazi.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Eqida.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Gxue.jsjs 5d400879af22f8c13d3375ab9b83e4c765e12e967c66a714c9e09bad5eae9d67n/a 
2023-05-18Jcxaap.jsjs 6325a36db9c4fb5af943871bce9ae9c80002f6d9379e71cd94bdefe0342b14f5Virustotal results 32.20% Quakbot
2023-05-18Ovjocft.jsjs 6730ba9eb12acff08b5c019bd8587f2cecef533f14a7ca9fc80e7ed001bb903cVirustotal results 30.51% Quakbot
2023-05-18Cdkpqoq.jsjs 91a5198c948c77a1f4e846013f6bb7d2ff376ca399e58f825e90cfbaf5c3c773Virustotal results 25.42% Quakbot
2023-05-18Nvwjnvoe.jsjs 34e3acc0e6ab649f51c734598559914d2597cbd6d5a224f09da4ccb7ccbd769dVirustotal results 35.59% Quakbot
2023-05-18Iympvgpq.jsjs f6bf73aa768753f4379e2df6f0094dda46beb48b879c76c983896434f67c0ab0n/a 
2023-05-18Mquo.jsjs 213ee67765673cf53e5f361c49a1bfe40187ecfa07f72bd5a77d13e1f437edf4Virustotal results 27.12% Quakbot
2023-05-18Ywqoaed.jsjs ad227c276250c72ebaf4c13e5d960347009d0762b8c2e696a35b36232e0eeff0Virustotal results 27.12% Quakbot
2023-05-17Xlpe.jsjs 03de8856a9267b9e96c1454bd5a13ff8d068076ae6a1b7ca1984367997fa981en/a Quakbot
2023-05-17Ynjd.jsjs 08a4ded15b1b100031a7d4d5816c32a45f5bf29a74bb677f99634db21d3cd646Virustotal results 11.86% 
2023-05-17Vapr.jsjs f11d7ad43d7a6c6cc716d06a9d41c96156d6ce0dc45d6add8d3039cae526e350Virustotal results 25.86% 
2023-05-17Jqhh.jsjs 86f81887bb6051cb0f8b8b3d948a6e4bbff1538e986a71386da56590e614f26aVirustotal results 25.86% Quakbot
2023-05-17Tgay.jsjs 494e69eca209ceb575b3ad74ff164605bc99c57a7621108280f95412b64e0becn/a Quakbot
2023-05-17Sptok.jsjs 24c2f222f6f2809f7c5dda15d789a41d9424dfce3714fe71bed9fbb0e077503en/a Quakbot
2023-05-17Mkik.jsjs 8eec4b2ca78d1d8b62a875c3a6b16a0a9053aeaf65f1e6cca22000629ab71432Virustotal results 27.12% Quakbot
2023-05-17Mgujkswd.jsjs 3d234411a958948cb4805e18eb29cd95fbd93086ffda9ed636c6d322523b5e80n/a Quakbot
2023-05-17Tlwtm.jsjs 018eabb71666dc41aec72587b841e2ae709590d998b0fd1fe67130e2cc332e9cn/a Quakbot
2023-05-17Qaunpra.jsjs be0478b920b6fef472303deea9755f457b882d88ce821ec4e4fc753d8a0fef3cn/a Quakbot
2023-05-17Ddupjgqh.jsjs 28a6ecde928ff48738a20c102f04c74595281419fe1c170acfc2b8af127fc03en/a 
2023-05-17Xvrc.jsjs 6fad6d4c92d30bbc2c919cb35c75c79e6af7eb04bbd61f15b8d8b0491065266an/a Quakbot
2023-05-17Zdflfht.jsjs b5f7cf7062ec108d0b12bb41a62449cbf179c3d503b0b4e15f9120e73faec2d0n/a Quakbot
2023-05-17Ctdrtwmb.jsjs 01a135e5e66a933136b7d1d9fd3d318e654e8993dd5b4afe2be7eb14a9612719n/a Quakbot
2023-05-17Tvidh.jsjs 5876ac1ceede64a94a62f4c25253bcd76a60c0cc696074695fc2bb6a84a2a9c4n/a Quakbot
2023-05-17Jbnpenm.jsjs 268616e19e88e9ba8cc14ee836ff938294db9d6412f3faff429fdc10ddbfc32cn/a Quakbot
2023-05-16Gzbhb.jsjs e869eb5c1e423b65e5b9b04aa566494c80142e609004594b4e1f418497db3cf0n/a Quakbot
2023-05-16Sykzja.jsjs d369c1b5dadcbff1edfbd5403818928654c9169bf26013c461b7ab018cf50f42n/a Quakbot
2023-05-16Fjaizqp.jsjs b68752be547da3bca866193fd8b9fdda40933a2622b33ede5ad8a4bbee23e746n/a 
2023-05-16Obasmo.jsjs 304f83c8b863fdf8d8994ba268dd001bc92688904b406e5fdb5c5e52f7671eean/a Quakbot
2023-05-16Rtzm.jsjs 53c5bd34a62c028fcfd9486db7704696d7c077a179235b8d842a3eeede02bffan/a Quakbot
2023-05-16Xgamctwu.jsjs 0dc9b05180c89746d51a543b553b916e7f75241cf2f1cedebbd4252abe13dccan/a Quakbot