URLhaus Database

You are currently viewing the URLhaus database entry for https://armeriaeantiquariato.it/ono/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633879
URL: https://armeriaeantiquariato.it/ono/?1
URL Status:Offline
Host: armeriaeantiquariato.it
Date added:2023-05-16 13:14:16 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:15:50 UTC to abuse{at}serverplan[dot]com)
Takedown time:2 days, 7 hours, 50 minutes Poor (down since 2023-05-18 21:06:39 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Moxutie.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Afdd.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Geeefkqx.jsjs a51b98df105de3f259cb9e467532c2c6b90dc058363854ab3cb75fe44b1f1dden/a 
2023-05-18Reypds.jsjs ed175d3585ab2d387e6c4a9420d8aa055d62ef6670fbe83a0f66d5bfaf943a92n/a Quakbot
2023-05-18Dokfhe.jsjs fed0fa880fd9812bea44ff765356fb74bdc116ba4a93d3e22ad855b9e789e299Virustotal results 31.03% Quakbot
2023-05-18Ehcw.jsjs 562698d61476d96d6f3b0fd847585b9c5e4d1f9eb96f8153ba577725aa0eb697Virustotal results 27.12% Quakbot
2023-05-18Vbhn.jsjs ef1c6b9ad4a7758ef25a4557fa7bf0a20ab6dd57c36474a91ef75620edd0974dVirustotal results 25.42% Quakbot
2023-05-18Qpwd.jsjs 31bfb0e9f32a6891aa3b4bb9c1caeefec664295de95b74eccecf9eb67a2b84cbn/a Quakbot
2023-05-18Ymifftz.jsjs 0b8b2630460c4baa473d458c5dfe165acc6e1cd41d684697d22599bce6fcf623n/a Quakbot
2023-05-18Ybdnpexf.jsjs 865abbd345425ca06fe788a0af4970d985cf2d622cd0ee375cb43dd5567afe23n/a 
2023-05-18Txmqnt.jsjs e8a4b575211295a78e536c4a374d5538f24470f6036d3a1e5ab52f149b6a5683n/a Quakbot
2023-05-17Zcfvr.jsjs 2810143d11f9ad7077972f807f2dc04a3f22746f81b7d8365d879e722c0b3551Virustotal results 17.24% Quakbot
2023-05-17Vjek.jsjs b77866fad79584d4eeba2fb19ac488731b788c0c7c1ca30001f91741db44e06en/a Quakbot
2023-05-17Betvaso.jsjs 009f072fec4afeeb62ee51fc61e387113eecca3d907b9784a9e4b79ca0c64ddan/a 
2023-05-17Btld.jsjs 6bf7410f1b32c7fad44030961607fb13ec400a2a008f5817485ba84c5c297175Virustotal results 27.12% Quakbot
2023-05-17Cptfwgtn.jsjs 56e1630e4d5a2e6b1c2e4e5494d4f0934129788140e2bb2894da4d50c48ece66Virustotal results 27.12% Quakbot
2023-05-17Tzget.jsjs abc48260d90f80894b8dce196c06da33c2c84c6e28e7f70c81840bf419cf2344n/a Quakbot
2023-05-17Iolge.jsjs 0769e73bc4ebc2ee5fdfb2e6d02b6a282085b48c709104d96e856380e8e4ecfdn/a Quakbot
2023-05-17Ocsb.jsjs af8f802f262b147fb2492cb0b5062b81f435da3c20a8b616ab4d7ebb64cadd0cn/a Quakbot
2023-05-17Tegds.jsjs c711e033fef9ed7350d03fe8b7e84329c3208af4c2f38053ad43756bc4d71016n/a Quakbot
2023-05-17Eiphaxa.jsjs 43436c0b512ebb897a00e6b35a6a60ee6b1f774bcfe5098c791e384d5ff6da8cn/a Quakbot
2023-05-17Rmhpek.jsjs 6ed2bd1f09f71aff539aaaac94c26317d5e6cdb371c6cd220e9858681c79fec0n/a Quakbot
2023-05-17Ooyrgwfm.jsjs f75c6d3b7ebd9362cf10f130c3a41fa8c1ba752ec63ba98fd9e7ad7bec3a92c4n/a Quakbot
2023-05-17Bwqol.jsjs 10114ec05bc6b652c609f078973216ea10e0085c905648a9dd82e9ee2add9088n/a 
2023-05-17Hfhjxv.jsjs 763c6dfb34ff90d77de5ba5787001b65db7c18f7e3c8db6f20875d8f52116633n/a 
2023-05-16Quevklog.jsjs 0d708698988938c95adfa35e6276e1bebee56b83934a9302c6548e188e77fcfdn/a Quakbot
2023-05-16Bhnwc.jsjs 977f05d12596fbeeb131adf3a45a469ca9046c22602ec59beed09d256557c9ecn/a Quakbot
2023-05-16Ezxkco.jsjs 2c87925e0dd6b1a2eb69d2be78b8c7a5d519d97cc0169b03267b0757f3cf8301n/a Quakbot
2023-05-16Evircugi.jsjs f8b00c25d52ed7bd0ce83df165ac60809820af42701f13634a284d9b9ea9f8d6n/a Quakbot
2023-05-16Ytvt.jsjs 0a31988b38a59f7a6da5f340f0d19236ad7212f8be498ac472ab074da1acc2ffn/a Quakbot
2023-05-16Jbhuben.jsjs 07cadd918ca98425542349fb8b18b698b22595ceebb53ab3c435a0a18b6b8f5cn/a Quakbot
2023-05-16Gpjxl.jsjs 0ddcab095d2d258fe0c311f8cae660a329bf1f2b8e17003c21ab4f79992c52fcn/a Quakbot