URLhaus Database

You are currently viewing the URLhaus database entry for https://nalabeaute.com/qul/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634008
URL: https://nalabeaute.com/qul/?1
URL Status:Offline
Host: nalabeaute.com
Date added:2023-05-16 13:14:54 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:02 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 8 hours, 17 minutes Poor (down since 2023-05-18 21:35:28 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Agxjmvwh.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Pxgtccd.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Zrxcksiv.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Pqgmz.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Yjpdfk.jsjs 38508113e24f0257ac38997594917340e48e869d933f1b6c2b8bd4dc5e7ab58dn/a 
2023-05-18Sphuid.jsjs 2805dc9f718f68c7daf0cae2b00b6ed8bd0a6e3a957fcf340055a17cc4ef7ef9n/a GuLoader
2023-05-18Kzqep.jsjs 76b1f9267eb932c85c8717778e7399af2196f31c3f1ee4b76d83a2cc5f2e486cVirustotal results 25.42% Quakbot
2023-05-18Voasllr.jsjs ba77ea0ae3afe4582d390d1930a3792bde2ba411df7e3c05ae156306c5cd46e4n/a Quakbot
2023-05-18Uwenymhl.jsjs c3e99de4200fa77aa025ca9c3691f352cd668d0a77b4f467305f66cb4f933618Virustotal results 16.95% Quakbot
2023-05-18Ngvfgajz.jsjs c183dc69a6e054260b5800df8cb1bdcf33338ca9f2d92f1b6d2161ca1fa1b850n/a Quakbot
2023-05-18Fsfvwmfw.jsjs b1c5cdb6f87ad0c3aacbf479218ede289571b85d30eb47defef749332b52c806n/a 
2023-05-18Jdidprsm.jsjs 66a44d6ecc0bff8550c4f8fd93b40851e019bac6297339dd180d268ed9bba451n/a 
2023-05-18Eltai.jsjs 828ab9b198ace6540bab66d12bff28bf5b11bb1258df06ae467240d2ff175f1bVirustotal results 24.56% 
2023-05-18Jtha.jsjs 47831ca3235332c96696b1add7425b7dcb044b9de06934992957a5e00cb4dadcVirustotal results 25.42% Quakbot
2023-05-17Zhtwggxk.jsjs 72c9727d22512473f4aa27d93e0c15ae33a95784d9804b057275d0d7d8b0a361Virustotal results 8.62% Quakbot
2023-05-17Wkbfaylm.jsjs fceef22558799ba34afb830f44f63ff2d0386112e3506a24549d220e7ab2f4d1Virustotal results 15.52% Quakbot
2023-05-17Itcyqvc.jsjs 2ae770725a34857b3a2ff3821341d0b0363c401b4588d1bd1ce75048f2b83a18n/a Quakbot
2023-05-17Wyntouqs.jsjs b87903d0aa16eb59b3bd58047ae31f7e370cc478a7b6d952e262fe4e56abb4e3Virustotal results 26.67% Quakbot
2023-05-17Yhyoe.jsjs 7cfdf6db2bcad8f5b911ac39a8da45e6a8bc3e53c287742c8afc09821a544c0fn/a Quakbot
2023-05-17Gnzxaxk.jsjs 3a16d7765c95e4f1c085fb18814d67ba3d65e6bf93e38d064ef74c1f9d15ac83n/a Quakbot
2023-05-17Ozfocbg.jsjs 4ca00c819ac67574145c0664985afbfd757621b4809ec157f14d22108aeacf8dn/a 
2023-05-17Arqx.jsjs e2fd875f7b6f930eab2c8c5d52bfe94525f508d9bad4b83465bd344dc85a490en/a Quakbot
2023-05-17Iedvhbwz.jsjs 5d307e4a1eb812101b07dcb03e019e0768751bd4353432e079e0b4146c1666een/a Quakbot
2023-05-17Kyhvbaki.jsjs cc36eba2ba4a53364ab439ebfa9f6edbb2efcc05bacc2b6e25ab287e63a2912fn/a Quakbot
2023-05-17Fxgy.jsjs f273d0e239c9a7fbc269ed6c2546d46357b2668eedf950c568b5afa04245e835n/a Quakbot
2023-05-17Recn.jsjs fc86f408057338528c393955f7826ba03385f0a8ab22e4d8cc47b1933da5fd35n/a 
2023-05-17Tueqgzgx.jsjs 3bd648d69fec4dff25054db7a39c2a545a1ae10912e735155b2cce1b8ed717ebn/a 
2023-05-17Vrspcvs.jsjs 6c49fdbe6ffb6091347e45d6d143f80045b91ee4de4175666e20e11bb9da4248n/a Quakbot
2023-05-16Vdtdycge.jsjs addf4b473cf4168df9863d4a76b99f4e49e8ac6a3a6acd9ab6f7ba6555a5281en/a Quakbot
2023-05-16Bwdkzal.jsjs 85e75b459472482ceab5a7308602c87f0e2316a02603287b913c667ed5f5a107n/a Quakbot
2023-05-16Uversy.jsjs 845aa67457309e8038e147223100d13f8182f72ae3b5a8120097c75fae4fb76an/a Quakbot
2023-05-16Srnimjf.jsjs 758824f01b4f82e8742ddd927e300b5e8a6a06a084331300ae19c4c756f514f5n/a 
2023-05-16Ffxqqa.jsjs fab9c6b9d764a33018129323dc9b55ccb236967f3c397a62e6a135b9679eec74n/a 
2023-05-16Wodesr.jsjs 2eebaae2fea778c83c7d03ec8e8bf1bb9ec2f872deafec9cd66de07d0af386bbn/a Quakbot
2023-05-16Sziftdep.jsjs 0edc0482bb44678f312b2e91751c2f91a1fa167a4e7897c92ce9f7ee0703bd3an/a Quakbot