URLhaus Database

You are currently viewing the URLhaus database entry for https://godivingapp.com/so/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634536
URL: https://godivingapp.com/so/?1
URL Status:Offline
Host: godivingapp.com
Date added:2023-05-16 19:10:24 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:11:29 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 2 hours, 5 minutes Poor (down since 2023-05-18 21:16:36 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ogzgojv.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Ocxwz.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Sbss.jsjs 94a383c0a64ac882691d1fa0b2f31687d06566c0ad577ba045183e121d2de551n/a 
2023-05-18Zdvp.jsjs 97961abc6b3628852a890d9f074e8095b28bd2f9f186169b33981286e6f0529cn/a Quakbot
2023-05-18Lgidapi.jsjs 683503e1ee6accf36b4e270156fa48982aeb9619157f07c35c1dbbfeb8a43e7dVirustotal results 29.31% Quakbot
2023-05-18Uvrwk.jsjs 023250d4f9af49d2f7968647280c712aff55b6146a5a06b7b302bab288a405baVirustotal results 29.31% Quakbot
2023-05-18Nekz.jsjs 1126eb773737ce63bcc031813a3893e30dcc5b6a0f018496a3e0106fdf1783d5n/a Quakbot
2023-05-18Lkugmzcm.jsjs 4ec189841fea600476bff49f643d0877dcdc3e3050e54e56abc5a7c492ed00dbn/a Quakbot
2023-05-18Sdnjyjo.jsjs 456c54257858cdc9347b6b71444659a256ae3a000dc1c82298d0fc65ba890687n/a Quakbot
2023-05-18Lcacjaxj.jsjs 70a531a610e47641bb1c9aa721282178341c6ccae5578f0ba31a38cfc5cad76eVirustotal results 27.12% Quakbot
2023-05-18Qytulk.jsjs 1539b3e778af6f644e932c0910705fec144fe2bbef2f8df241b0d4bb821d0fc5Virustotal results 29.31% 
2023-05-17Ckcinknn.jsjs af1b94948c602627bf551b38dae50d6be3c349f5b15e7fe1d2a792e047809553Virustotal results 28.81% Quakbot
2023-05-17Erixhtca.jsjs 0efda647b9e6537d80702573e14dad4cae7edd5bb92d94eea0f136b93fdc03b7n/a Quakbot
2023-05-17Novg.jsjs 3ff223428a9d2b7b897fd823e4add6ae4cc119c86e47eb073bdbf5a578a17226Virustotal results 20.69% Quakbot
2023-05-17Fome.jsjs 9b57a0a1ea9fbea6fc63b1a41a52f5dc8e9fa5facdff20d031096a0075e9c715Virustotal results 30.51% Quakbot
2023-05-17Aiiwato.jsjs 3e294b83a7ced7203c04c79e0e2893c636344ba211f59ff49a66d91a93fe3bc4n/a Quakbot
2023-05-17Hbnbi.jsjs 44d23f66a1f4b2d201da3bd9764d30d67431194d1ffbbc0ee587ea63d892dee1n/a Quakbot
2023-05-17Lolyh.jsjs 8496ebcccb2676a1fb21ed0fdf36c320fabcf9036d275af7acc025b0182e7963n/a Quakbot
2023-05-17Glgt.jsjs c66769c1beccde8a71bc20172ba3978dfa20fa8e27c21976b94c10327af6d4can/a Quakbot
2023-05-17Loayx.jsjs 1b820ec440ee64efeac4e44c6f3fe49a1043109e3ba2abcd437a29a66170cc5dn/a Quakbot
2023-05-17Ebrkyek.jsjs e2e638f9c8690dfaec3947d5274623527b08b46b1c3d7bfb7f0ab404f81c5625n/a 
2023-05-17Cpbnl.jsjs 95a002419828c7f5476f4f06cd0239b9ef364a512d1951d05e211d2a76f2ccb9n/a Quakbot
2023-05-17Hzyhc.jsjs 22a6a44cfdec658c6cf39e87eb376e87a3855ab5b11d6c82c013bc5829b2884cn/a Quakbot
2023-05-17Ddtkppc.jsjs ebc7a4b7dbfffafbd387c62b0b6767e34163944cd55f61db60185684d11aac53n/a Quakbot
2023-05-17Yvpt.jsjs aa4d711aa9a203aa9a87c077f2a9e9ad9a1e27e89031eff09d559c18816f7cfan/a Quakbot
2023-05-16Cgwg.jsjs 23c66fa7dd22ac266a376995b8fc78b054cbcc963589f52c4664330af36f0f21n/a 
2023-05-16Apecl.jsjs de9be4213d4ce826d198bce66addf2102dbcd9d0fd6489ba8cbf2ae7cdf2e342n/a Quakbot
2023-05-16Ikfgbbx.jsjs 97aee74d7d03bfd23034856b8f2e52e29c24456a28bf10c65b4d28924a660b98n/a Quakbot