URLhaus Database

You are currently viewing the URLhaus database entry for https://noor786110.com/cru/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634131
URL: https://noor786110.com/cru/?1
URL Status:Offline
Host: noor786110.com
Date added:2023-05-16 13:42:07 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:43:29 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 9 hours, 5 minutes Poor (down since 2023-05-18 22:49:27 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Kmmzp.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Mqzb.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Bveosy.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Krgn.jsjs b506350897a824484b893d2bba312f8091478e5825643d2a2c820ca83480a1een/a 
2023-05-18Vfcnlamj.jsjs 8ee5d86b74cd803753d211be4c64578d8d39e7dd487d114bdbe044505063bb7en/a Quakbot
2023-05-18Nlvyypyd.jsjs bc08bfae3a441cb9485634aeda5f5ae4cbbe5e36cd98ce7b2812cd62ed4e5034Virustotal results 25.42% 
2023-05-18Reast.jsjs c1b685d3448c37f78c922a2a19a51272e6cba29bcc9f50ae1266bc064074f257Virustotal results 16.95% Quakbot
2023-05-18Nsae.jsjs 7723afb8d2a1417a6f0c808e628394b609e66227688064323ce47b25cb0505bcn/a Quakbot
2023-05-18Sphjuwnf.jsjs 6003ec795de91a5d5a9a9abb15e037b5f4dcd8cbf43bac5330005fdda61c603aVirustotal results 25.86% Quakbot
2023-05-18Satzd.jsjs cb296a47f490cbc70541030b87a0b2d9eb6c1253da849e9e37e7912f2fff796dVirustotal results 35.59% 
2023-05-18Tskvafcj.jsjs 9ac768cf3025869132bdb78aad3f4505cd8dd7e5ddc218e64d6645ba8db5e4f4n/a GuLoader
2023-05-18Zxpiegzc.jsjs 2ef6e700c619c1ace05075497393d8ac827d836ec052de9b6a71a0cdcd343141Virustotal results 24.14% Quakbot
2023-05-17Rdjl.jsjs ddfe74e26faf2b35c9062f09a66b41c79d391c1658c3fa8b4e2ce20752a2b05fVirustotal results 27.12% Quakbot
2023-05-17Azhtkb.jsjs b9a4b8691e7de63f6af1a61319d16827e3308ff248981ca1c9d815fee2a1b93bVirustotal results 32.20% Quakbot
2023-05-17Welrjc.jsjs e98ab08e4897807987344800297aa41a72fc207a57b0e89510243b3b8ad0e144n/a Quakbot
2023-05-17Tsklp.jsjs 716b277dffdcf3099c8c86e0198ddab7a5d55627de582e5b73e900db63fed67en/a 
2023-05-17Kjmvmo.jsjs 35a99626b0db91409ed1ac874964033c1490a20549ae611e95fa7f81dbd98d44n/a Quakbot
2023-05-17Gvrmzei.jsjs 307a3ef8bc1930af1d46fc60bac9820950e278feee14f7a931ac745613568698Virustotal results 19.23% Quakbot
2023-05-17Kxqbs.jsjs 3f81d638187365133a7541ec95cc8cdedd33693b4fd6331e5fddb2281147b873n/a Quakbot
2023-05-17Wxrvx.jsjs 6402596247d3169f011ea2d2782fe9fd08589505dddd8d50dacdad6a4357b5aen/a Quakbot
2023-05-17Barvb.jsjs 689d81d6f796a7b4c96116d4e398983d784ebda18ce9397d1aff675b26435d6bn/a Quakbot
2023-05-17Cwqqnqq.jsjs d4d800ab00dd0b6eab800e70b69d3fcf179b457c8ae75f371ab3df27d4416ee5n/a Quakbot
2023-05-17Skvcpl.jsjs 16eec69d4105969451788fbffab716081fcd07ab717e5dc573dd9c7b8b3ce637n/a 
2023-05-17Mbjjtko.jsjs 46fec60956525cf771c23ff9c962d95e99d02dc5fbcca19c370ccd83116c9f72n/a Quakbot
2023-05-17Copvvve.jsjs 758780175a758f0c904db76e950cc592c759f7c25e04a43fa9b774b93d6a7384n/a 
2023-05-17Kejzhzme.jsjs 5cc94bce66f594fb4fe5b0596b90606016d2d9c81a5f01b8ff03f185bb75c325n/a Quakbot
2023-05-16Bpnj.jsjs c2edfd7aaddea7e835aa2d61e97e330d045f86597d3892a8fdef15a65457d53bn/a Quakbot
2023-05-16Ibwvvh.jsjs c1fd200f89ffc8cca07fdf1ab8461b35f42260e118300efa28e63e627f1c132fn/a Quakbot
2023-05-16Togq.jsjs 1dfc923140b152a3e9dfe22fec6e7f4988b5490f5ea6689b61d4cc66a74aed8an/a 
2023-05-16Vbwragjp.jsjs 6567f4bb4663337051612e1b8d0292b6694ee5a5f510602d1b0d0a3a788d1c97n/a Quakbot
2023-05-16Tkrkfbj.jsjs f276a67114663005e29241416c09281e73c804b882511e5bbbc4fe2298663232n/a Quakbot
2023-05-16Wnrvsbmv.jsjs 734c8997dfe3234ec984d8cdf2a1800dc82178079c297a8febc21a51eb9cd027n/a Quakbot
2023-05-16Vblez.jsjs 0eb14b152f0be9ddc489f0f1a0599edc9bd53a75f67549fcc144668536e56470n/a Quakbot