URLhaus Database

You are currently viewing the URLhaus database entry for https://book4noon.com/uibv/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634035
URL: https://book4noon.com/uibv/?1
URL Status:Offline
Host: book4noon.com
Date added:2023-05-16 13:15:01 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:27 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 days, 7 hours, 47 minutes Poor (down since 2023-05-18 21:06:12 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uaxskff.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Wzge.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Wbdm.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4n/a
2023-05-18Xmwh.jsjs 8496ebcccb2676a1fb21ed0fdf36c320fabcf9036d275af7acc025b0182e7963n/a Quakbot
2023-05-18Gxrfu.jsjs d072c0958caad1a6504236a0de9defd899adf9e6deedeb1cdeba1e72229b29d8Virustotal results 30.51% Quakbot
2023-05-18Vwmfra.jsjs 9fc5c95367df0d42df001590faddb4edf2e71a19e7159cb210d5525553462459Virustotal results 15.25% Quakbot
2023-05-18Fvoji.jsjs 6da4a8bacb02c6d1b3251c5978545168c0712fb14b5ec2731a867b73a3daeacan/a Quakbot
2023-05-18Hjrg.jsjs d5cf74860b7b3a07c522d435a8360406d7c4a5575bd34a1244d8d0c1426bdb61n/a Quakbot
2023-05-18Tqyunxic.jsjs a9d658acf1c13639bef4615e65fcd8eaebd3b1d0c14ee826b7268e893878e5a5n/a Quakbot
2023-05-18Ufmbpjs.jsjs 72495f905e654ea365738e7e3ac93200be27ad81df4327197c8d1a1427209a25n/a Quakbot
2023-05-18Twlszs.jsjs 257dab59e71c1109ffbf0b4ee1568df9566b886ee56301a089577a0fbec29fe4Virustotal results 8.62% 
2023-05-18Uzpivwha.jsjs d2ecbbc4d10634ac3f47ce638df6c4302d7335ab985c09f6accdfe4df322dddeVirustotal results 36.21% 
2023-05-17Jlrport.jsjs 32710b418e9ddc449d0548590b62ac23975ad6efba53cc55cb1551326e182cb9Virustotal results 30.36% Quakbot
2023-05-17Ijplhj.jsjs e33a486361f2b596983444fdfcab380bffa678c31788687e1d8fb8e9aed9f6b0Virustotal results 32.20% Quakbot
2023-05-17Givew.jsjs 784d0c23a7299fe8f5a79ce4f83765cd48535cf1afc25d542a0f854f8049d149Virustotal results 27.12% 
2023-05-17Vmxktlim.jsjs 1bb623b986a2a31d7b68f61ab99a793274bcd030e6ff4daedab6e150252b27b1Virustotal results 25.42% Quakbot
2023-05-17Cehaaifm.jsjs a93a8bf8a31ec8306c9567bf9a32a827765ff0e798aacba99ea917a481f43f7en/a Quakbot
2023-05-17Jnyeeyc.jsjs 36fa7b7d4e7fc7c9366c2fa6533c47fd96cdc2d9a6f2c3a9025fc4271c5d4c18n/a Quakbot
2023-05-17Zzhocg.jsjs 27f17e9ee4e8f78f3e02acac452da67130c961c7c0d07e9ac05fe68ed2f3c07an/a 
2023-05-17Polfxtoi.jsjs 43d63de96591c384b70bfffdfb959160bc7fe103595aadaf0b43111491b83b2dn/a Quakbot
2023-05-17Ncokuq.jsjs 532692f2f154e0428cfce6c8ee1df9d64f56bd10fe4c5ebe5147151616ce5210n/a Quakbot
2023-05-17Umktxd.jsjs a54688b385a28d342826ad0ad269a861b06384789aa274aa734b06acb115006fn/a 
2023-05-17Inceea.jsjs 0d955436cb4b750a8103d00df00a0fc7e747edde9a39231b2ab194fcd964ec4bn/a Quakbot
2023-05-17Nsvxoqxb.jsjs 0550f5313f201b2403e6c08bcfcaa00948b99a5cd9ca825c5fc670213194f115n/a Quakbot
2023-05-17Xpthfv.jsjs c6580fcb710330c18962c2bf2229741c364741f62553342f1e9e80c2a73b2a7en/a 
2023-05-16Dgsie.jsjs a36fd59223b31a9aa1e026c9d3f2613cf8853b8b582241b9e051ce7f98d0abc5n/a Quakbot
2023-05-16Zgxvqu.jsjs 4c9bb29dd86b9bce387658f648e97aa7c71e9d59d40b85ecbb51cc83d3063788n/a Quakbot
2023-05-16Ofhgbjvd.jsjs 0dd6160f8beeb1c056737ae24438fda0416be8cdb5cd570c274a8142adab083cn/a Quakbot
2023-05-16Qtbzyu.jsjs 7f8f89d57918529ba6ed6c878960b957f549b2449d389abf4d663e1aaba6791cn/a 
2023-05-16Noogamd.jsjs 57403ce071a0185711b5c0a36033baf5296ac8a5bc35175e33117590178b4699n/a 
2023-05-16Bdiof.jsjs 5edc527ac14d63c06cab3b888d06c840e10966926b0165a7bd6e65743425797an/a 
2023-05-16Pewl.jsjs 88b8295b6834acdd644b2729ff4d47c0f6765d175a8cad1d088c031471809e2bn/a Quakbot
2023-05-16Tmlhs.jsjs d0dae8f5d28f3cc4d2c744bb042bdf353911879bc84ba902402140b84aaa9ff0n/a Quakbot