URLhaus Database

You are currently viewing the URLhaus database entry for https://doctorab.org/nu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634484
URL: https://doctorab.org/nu/?1
URL Status:Offline
Host: doctorab.org
Date added:2023-05-16 19:09:12 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:10:29 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 3 hours, 43 minutes Poor (down since 2023-05-18 22:53:56 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xbjk.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-18Hiang.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Qhlssd.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Skdmu.jsjs b791c6fe50d67be4051d4695a898a67c06a3f28be8fa9f0ba290db28c8362905n/a 
2023-05-18Iyekn.jsjs 576d80e7bad2be3b3f4ddb0ccbe067bceabbc990bb96e11007cc74c2d6ad7bean/a Quakbot
2023-05-18Pste.jsjs 72b50fe52615ed2facfe5a1517ed75f7ba6d2d98e26968645dd646186fa5fef9Virustotal results 24.14% Quakbot
2023-05-18Qfet.jsjs b7aee295279db7ddc9a5aaf2c89b1395f0a2c3ad92cabddcb41b024dbeff9c64Virustotal results 18.64% Quakbot
2023-05-18Ctbys.jsjs 66718c6f0ac9419d7f5bb30cef5272328e503b226e7ee6157072e26782f6421fVirustotal results 16.67% Quakbot
2023-05-18Ddzzcae.jsjs 9459a0cb6bc3dff0f7972ac6852fb2f11dace3df33eded8be946a0ca5f1160d7n/a Quakbot
2023-05-18Hcesqre.jsjs 6d5e3d77360658771bba4d35e8dd94a77d30f33a7c30ab86b66e271b54d2a638Virustotal results 20.69% Quakbot
2023-05-18Ddhxp.jsjs 2c6c3f6ffb898b9a29cc0a5ec84ccecf30800496946b378d5558f81798278c3aVirustotal results 32.20% Quakbot
2023-05-18Portigcb.jsjs e2cd2a44ac9c613f289c14a9d30244223f9949818db49dc69c73a5efc442a948Virustotal results 28.57% Quakbot
2023-05-18Rktise.jsjs 7aabd12a63a4289e6a5f5fc62d866ed2ade8e917a6f2d203bdfd37c0f87ab265n/a Quakbot
2023-05-17Iiigqxc.jsjs d2338cd0376171b31bef79e7bc05e3954d3c61c6f23184804a1a1110dafa3d36n/a 
2023-05-17Wtjdv.jsjs c419bc2833e48f8f26166ef911d3915be8fd0619ac6a0e0638813a4404df6979Virustotal results 25.42% 
2023-05-17Qzymoh.jsjs b1580417444140f2311d1f0098c4af6163f27ee7fc99281c6c6904870fdd88e3Virustotal results 27.12% Quakbot
2023-05-17Weskgyvh.jsjs ace729a8273c30f923532f7f1a8c2d214aeb49b0c3109d8eff64612384b29140Virustotal results 31.03% Quakbot
2023-05-17Pxygym.jsjs 94482ada3a27f9e8cf8f7b554597969eef03e0593d496ba95205fdf735ed010an/a Quakbot
2023-05-17Fkhqvod.jsjs 5526b208f51ee2b6adbf6b588401d5c1e058973988c16897fef27cdf25f2a51an/a Quakbot
2023-05-17Huke.jsjs cb6a65f1e6220e908455c9dfaf1b69114b9b0c5666dc2b80f597d2c1e4ab29c7n/a Quakbot
2023-05-17Hvmrvpvi.jsjs 386d7cea5c5e9b551389031e363eef87160be9cd2dccbdfa5fe73674e361ce8en/a Quakbot
2023-05-17Qwqseski.jsjs a37aab1bba9fee77633ea90933ea0a8bee0b957862b009de913a1ae3f141413bn/a Quakbot
2023-05-17Itohvce.jsjs 4db4388b30b75254a1308657e79a306f10ac39b0f17e215808b4d05c6b8ecc76n/a 
2023-05-17Bvzyf.jsjs 425c7291e50085456eb7cd7ed91d1afb43e011ac856cfa4ad00435e3c8f0ec7dn/a Quakbot
2023-05-17Exvj.jsjs 2d43bab5e77ff7f7b93f847ab3112a0a76cdcc516f9434f7599d674a73785162n/a Quakbot
2023-05-17Igumtmva.jsjs 56cf4075f46f8629d912a18c1fd0b7241034a3a59e9d12b935a0b6565c558657n/a Quakbot
2023-05-16Uzjgktv.jsjs 9160e6a934e735bf8cad599d2f8b9c3bb0183ff10c0341c763b084c830f4f53fn/a Quakbot
2023-05-16Grmwyk.jsjs 90cdf7011ffa59103d5e0b24803d36b31a5ba227fe4b177c2ce561fd47a1ebe8n/a Quakbot
2023-05-16Nogakfkp.jsjs b6df20c34ffef41251bd25d0db942ad20d1438a5122dfac58cbb9715af60974dn/a Quakbot
2023-05-16Pjmrnt.jsjs c1e60cd8c6beba7eb86df01eecc9e502bf2a77014343c991341a0174baa48229n/a Quakbot