URLhaus Database

You are currently viewing the URLhaus database entry for https://divine-project.com/oat/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634491
URL: https://divine-project.com/oat/?1
URL Status:Offline
Host: divine-project.com
Date added:2023-05-16 19:09:14 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:10:36 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 2 hours, 57 minutes Poor (down since 2023-05-18 22:08:21 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Tigdcnh.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Dicwj.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Jwpw.jsjs f364589d1ceb0991911e6bea22a0ae624ba2e77c9af35e1f232461748d65556fn/a 
2023-05-18Vvba.jsjs 47838303934003e958511bf93e4b40816c144d7ddb6c99ad7cdda7145ee5dcf8Virustotal results 25.42% Quakbot
2023-05-18Goug.jsjs 3d234411a958948cb4805e18eb29cd95fbd93086ffda9ed636c6d322523b5e80n/a Quakbot
2023-05-18Iibvfwto.jsjs 78a09834bde88bcf04dd934a793540b810b090e90efb96a977c2477be294fc75n/a Quakbot
2023-05-18Bbxxnp.jsjs 33f33ebc5ae78bdbf3a9afc064c64f1121c0214e1305d5567232cbc8779ab8c3n/a Quakbot
2023-05-18Ywzo.jsjs e7b23f3002dffd67a5026b9ae031fe92c033bd7c37c6bb15323d3bb075275d89Virustotal results 33.33% 
2023-05-18Otucq.jsjs c183dc69a6e054260b5800df8cb1bdcf33338ca9f2d92f1b6d2161ca1fa1b850n/a Quakbot
2023-05-18Aurp.jsjs b11ddd3e32db780631dee2546f8eb8498cf1976976b4f9b6229279881aff3e12n/a Quakbot
2023-05-18Eyre.jsjs f5a9de314dd0e63ac6262d4d17d66999b1a0ef8384756576c26eb7623a678f71Virustotal results 25.86% Quakbot
2023-05-17Wsxmj.jsjs fecdae98fff4b89aadb8c35ded8061bdaa126fc12f3fd482cbcecd53246c1c0an/a Quakbot
2023-05-17Mexjsfhz.jsjs aa29c7434c1bdbe52fd461a295dac0931392a0852902d70bd91693bedfc48375Virustotal results 31.03% 
2023-05-17Xsbqfg.jsjs f4454d45458f3aaadcdfc328fc4107a6c670b1c0e04df1d476ca56e831b83818Virustotal results 27.12% Quakbot
2023-05-17Cjeyx.jsjs 1f26839da60e55672a1ff564cacf4050f50673ab46f7c13ece884b64e8db290en/a Quakbot
2023-05-17Pwlyorr.jsjs ccdaaebf2ae2ce525ab5ccf2b4d74cf6b58e7d9515c21c0d46e2b8e0709eefb6n/a Quakbot
2023-05-17Nlqbc.jsjs c5a390d1bf67c2241e5a9cb33cab3e83b41d4319c494c9f15d864cff3015e95dVirustotal results 15.52% Quakbot
2023-05-17Tunzl.jsjs ad227c276250c72ebaf4c13e5d960347009d0762b8c2e696a35b36232e0eeff0n/a Quakbot
2023-05-17Uoye.jsjs 6d790992a3828c5f421e6c85ac319d61de4eb5320ff67d91b8e5d4577865de5cn/a 
2023-05-17Ghws.jsjs 004dbe85cfaf5be656ec7e97ab8e3172a38ac9ffa1bb6baa860c540c85aec52en/a 
2023-05-17Mdbjy.jsjs 356afb5bfdba55a7914ade1335ecedbca5fd16c0d5c54e783c4b3c97b58b6b9bn/a 
2023-05-17Rioypi.jsjs 20ab16ba7dc23f98f33307ff9be483c0a7531508adb95f986d00347b3078272en/a Quakbot
2023-05-17Xizcloiu.jsjs 91e628abd291bae19c730982ac36d7f93d18fbb37d23bae64a172f866feab418n/a Quakbot
2023-05-17Kbrt.jsjs 716a6b8f21fdc8e8308e06c56beb012717e89fe6cb3c61f4bc85e04b838de9a3n/a 
2023-05-17Avrs.jsjs 3ad5311fb6ea2d0f0ba6db4642f1b8c97ed98dd396ec87f97d6d100cc3b38a53n/a 
2023-05-17Obohfmot.jsjs 0aa1def1e2b4ea391626dd3caf0cb037eb14d0eff9a0667708548ff6059d2285n/a Quakbot
2023-05-16Zvqjbfwu.jsjs cf19ee50d1ad6992f245489a7f62054930d7b573a3d65d8c1142d8d541f10c14n/a Quakbot
2023-05-16Nkmug.jsjs c17afaa69dc7d5c8817a25ecff73f9772455ef1004157e44e6ddf490f2a2ad31n/a Quakbot
2023-05-16Zwrmiu.jsjs be87ff395eaa48024fdbf3fd0d8eae429cde71c01238a467845cf94faf1a83b3n/a