URLhaus Database

You are currently viewing the URLhaus database entry for https://onlinequranforkids.com/ct/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634566
URL: https://onlinequranforkids.com/ct/?1
URL Status:Offline
Host: onlinequranforkids.com
Date added:2023-05-16 19:12:12 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 19:13:12 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 1 hours, 58 minutes Poor (down since 2023-05-18 21:11:20 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Lxgb.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Rzxfhkrg.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Pvkzlxbw.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Ywfkfcp.jsjs 296869c2b26b38f807c0445c68331a28b67be3de34638012c7ac373d583dc562n/a 
2023-05-18Woxtz.jsjs d50736e0dc6f86a7295550e45d34bcb51be1915a810402b50f05881002c45135Virustotal results 22.81% 
2023-05-18Kocdumr.jsjs e000b46c0d6abfd08c10602eb092657cdf4c49e578302729b7d31ae55a978a5bVirustotal results 18.64% 
2023-05-18Agku.jsjs 9b2f8c74295c1bedca1e85a34eca84634c652741d93c24d9c5586926552a77a5Virustotal results 25.42% Quakbot
2023-05-18Hoxu.jsjs 5ed8c2a8ffd44a6f80d52c65210bcb3ab9bbfc42a217a03db9d435fe66f68833Virustotal results 25.42% Quakbot
2023-05-18Dbnpkzz.jsjs a45416e3d9aa47760feeee7375be42c3748b04b0d9c6c573bf4db2cfa07929b5n/a 
2023-05-18Kgua.jsjs 8b5a063138d39c424fbf7ce7022dc972afa3c2df792b3a030272c1c77490dc96n/a Quakbot
2023-05-18Gtlxac.jsjs 714d6297effa9020249e19940853d50dcb2ba31d5301a716f34ddf73f9a58bf1Virustotal results 28.81% Quakbot
2023-05-18Kevfl.jsjs e378d6c2c0b5f5ad7404ae59dc73fb118bbc687f0b78b8526939d18e1a151bban/a 
2023-05-17Mdmo.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2Virustotal results 25.42% 
2023-05-17Gnoxc.jsjs a5e07fd19c36096b65281a4da6788fdb724e4cc4be6fae21497a969c1255a622n/a Quakbot
2023-05-17Tqxmtux.jsjs 683503e1ee6accf36b4e270156fa48982aeb9619157f07c35c1dbbfeb8a43e7dVirustotal results 29.31% Quakbot
2023-05-17Lpahdjh.jsjs 56e7ef28abd5d99579c0cda0cafc94f64335c3b99a2c4a88b27c75bc943583d6n/a 
2023-05-17Ojcymxh.jsjs c936abc12d461d92641e807274f5df2fb3c02f2e568920845092ed9547299bafVirustotal results 8.47% 
2023-05-17Ydxrd.jsjs 9fc5c95367df0d42df001590faddb4edf2e71a19e7159cb210d5525553462459Virustotal results 15.25% Quakbot
2023-05-17Xdynkznd.jsjs 83743f2158c1cfe6f65635d6a1c2aeec71545802940ab5e083fa9d3a98d650aan/a Quakbot
2023-05-17Wykbwmxc.jsjs 2e390e1299de680801e5969e46cfca98d05394034567c06f0b89f7c40250126bn/a Quakbot
2023-05-17Wqbm.jsjs 2c8a84c7cc68b7a13ad0fb00b6497f3bf86196ffa8add8ff6cf439e7ff36096fn/a 
2023-05-17Svjafqur.jsjs 1b27bb588e499627533bc9c215a116e0f7bcdb56d64d3e53477172abb689852dn/a Quakbot
2023-05-17Akjnrojw.jsjs 175f3a0415bec94b852224051df36e2a7dbea3721d2815ea34d68fe7d0a47fd2n/a Quakbot
2023-05-17Umfne.jsjs 15899e525688f3ea95375ea80a4be39087a1f3030df3e93bbf23cd998b1c2ccen/a Quakbot
2023-05-17Pkqrobqn.jsjs 3624898de6dac607793840e8f865accd022f56a05d44ccccbdbd19352410db08n/a Quakbot
2023-05-17Etrptd.jsjs 3c0ec589fa247a13961af600324c05b6e9b677ec559c0f5b324ea9df568801c5n/a 
2023-05-16Vksborcn.jsjs 38aef337a1fa11468e1559b7b6f3afdb1d2df69ee7d7a3455a352a1ca22d8157n/a Quakbot
2023-05-16Zhalp.jsjs 5f8076fad78ef656d682278d75222a7a8d411a746e6420cb89e49b02e2de1651n/a 
2023-05-16Wrspjm.jsjs a3410eb2356903b009368434bb5422e7f4d7ab209d2f00a9bb17219545806005n/a 
2023-05-16Yzdlu.jsjs 3573a8dbdce8d549e03de0e8f37c1699b085b24caed410f91f60fb5889622384n/a Quakbot