URLhaus Database

You are currently viewing the URLhaus database entry for https://alietihaddevelopers.com/idf/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634441
URL: https://alietihaddevelopers.com/idf/?1
URL Status:Offline
Host: alietihaddevelopers.com
Date added:2023-05-16 19:08:12 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:09:08 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 2 hours, 25 minutes Poor (down since 2023-05-18 21:34:36 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lxcg.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Nqha.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Bbohokw.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Cvdv.jsjs 1c0af10cb305c3741cb289913998258ecd97f888e28f2fb3ca92c143fd00cf29n/a 
2023-05-18Cngo.jsjs 0c1a4acb8216ade3632625958fc7427a5f996f5570d05d649a0e49be5e748ee9Virustotal results 27.12% Quakbot
2023-05-18Sxla.jsjs de678b4a37c6c15a808f0289a0185302b696546ff234a9c180ca99ac8bb1f313n/a GuLoader
2023-05-18Pgexmmj.jsjs 10f759e97a48df574fc941e1fdddf412b2e5a598d13829c47c202527d7d36ee6n/a 
2023-05-18Wfdl.jsjs 020f938e3e5a80465883b947cf72e1604c794e693956eee1cc4707135129fd43n/a Quakbot
2023-05-18Uyvvmm.jsjs 6a36fcdbced70acfd047d3132e249ef81960cf97f62f9e391e672db0ecd19f13Virustotal results 27.59% Quakbot
2023-05-18Gewfjyjy.jsjs cd8a39cd43a8cbb2e0c04b201b7df230226fe2dd696ab5c20c9ecbb16cc723f3Virustotal results 25.42% Quakbot
2023-05-18Mbzh.jsjs 8cb9812b4c0409176b2f0770497520692218130496cf0a2a363b4606ce28f506n/a Quakbot
2023-05-18Hfrfprvj.jsjs 71122ff461bd77e00f131eb7f52d813ed7a1fdb3262bba2adb83ee04085152f9Virustotal results 34.48% 
2023-05-17Sipm.jsjs 7a4ab56c0029ea06eceabbc4e8b9f005b37b97d1ea376ed3db95729269780e17n/a Quakbot
2023-05-17Ftwbw.jsjs 724461f309ab96d511ced805b91951db475a6c036216777c4f4570a3ce7fbac5n/a Quakbot
2023-05-17Vedx.jsjs af1b94948c602627bf551b38dae50d6be3c349f5b15e7fe1d2a792e047809553Virustotal results 28.81% Quakbot
2023-05-17Ouidubn.jsjs 2312d94387e675afd3db56f1fd5419a3a083bea7bc690341fa3d49d3e3f69f53Virustotal results 25.86% Quakbot
2023-05-17Tpbgvpo.jsjs 0af9a445f31e51c20a58fad5f35d353da59c49e684bf1db02c436c4d7f7f18a6n/a Quakbot
2023-05-17Uaexxjwp.jsjs 6f741f3bd19d3433e0618cd31b85f73aa09fb1dfe670c9e5a8e0ec01cf274495n/a Quakbot
2023-05-17Fwpjqc.jsjs aa49eea2c5b828df4f85742d3d76bc365ee6c18721795dfe567bd8be0b360d61n/a Quakbot
2023-05-17Ciiv.jsjs 1a0183dcea4c1a3db677bd84735f9523e6157383fd5aedb29d1e2518d36fa505n/a Quakbot
2023-05-17Ryqm.jsjs ccb5c33e4dcc6f372ff39930cf0e15ce5ddcc29cd52b962efaa6b8f1cfbd9a86n/a Quakbot
2023-05-17Bskshglq.jsjs 36f14cf210a0f171cac2c9809ff83fb33b459b03d8cd31214909b974a838d296n/a Quakbot
2023-05-17Wppmd.jsjs 8099118ea84b2d44e55e8cd568ca477ac2a2e848a87cc5eeef3f246d10fec1b3n/a Quakbot
2023-05-17Onja.jsjs 8e0627fda4e47f17711e0e2460a4c6b9ef2be3af0701f990423a03fcc16d538an/a Quakbot
2023-05-17Cwcelsbp.jsjs 5b8d6edfb1bd48d169e798ea354fa5c4a015aba49166636d0e0d3f75310a8943n/a Quakbot
2023-05-16Kdteff.jsjs ad289dac791dde2be6405c5dcd736204dcb342ac804458a2d55540398ad67b84n/a Quakbot
2023-05-16Nlugtn.jsjs 2236b99e68b50e02ad287cabb354e1b4e7a85790131022b8d50220aeea96880cn/a Quakbot
2023-05-16Enxpdx.jsjs 6dff1ae5d2e9599da062f40dbf642c4af0b481da8f5cf0766ceed0f2b024aa6an/a 
2023-05-16Dhsuata.jsjs 61e65d7bab09924954a0cde97379c4e364e2cbb26d97b7b68cc381d8d86713afn/a Quakbot