URLhaus Database

You are currently viewing the URLhaus database entry for https://redwebcreations.com/aoli/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634603
URL: https://redwebcreations.com/aoli/?1
URL Status:Offline
Host: redwebcreations.com
Date added:2023-05-16 19:13:15 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100116763 created on 2023-05-16 19:14:03 UTC)
Takedown time:2 days, 2 hours, 21 minutes Poor (down since 2023-05-18 21:35:09 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Saouoquq.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.33% 
2023-05-18Lphzlet.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Ywmkm.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Xdctdsc.jsjs 395ac6ede5000914172a39d9d0daf5999e64d0f63759b212aa30a1666d246a42n/a 
2023-05-18Tcyz.jsjs 9a649ac76d537c5f4ceb023745e2fcb3a6ed8443c46ac1f2dbd7da98f0487deen/a 
2023-05-18Pjzwf.jsjs dc7a9209bb0458b585fb71acb0ae6a651d790217507b141df605e7290800960cn/a 
2023-05-18Ioedj.jsjs 6e98b0ad9b6fe81e7dde4a5e76cddfdc25b19695ca702e4faf95f45dfc5a65e4Virustotal results 11.86% 
2023-05-18Pvez.jsjs 4f9c04f40501ff342f07c66108d89ffff23f8fa85ac574a2829cd65a757aeacfn/a Quakbot
2023-05-18Istr.jsjs 41d25fd2c9445a58f5ae64b05b6042873508bfb85efe4b1b00c3c1b03c4f930bVirustotal results 27.59% 
2023-05-18Vxdwnpv.jsjs 3c55d89d269d20d6852bd0da433091d1fb247c736acddefdf23c414213857e73Virustotal results 31.03% Quakbot
2023-05-18Nicqrvmr.jsjs 44d23f66a1f4b2d201da3bd9764d30d67431194d1ffbbc0ee587ea63d892dee1n/a Quakbot
2023-05-18Ypdl.jsjs 340674eac99b309a0a10a07f5d961e87788e88c4cc2f218da6cd61ccb196deecVirustotal results 11.86% Quakbot
2023-05-17Zdpxpeqj.jsjs 62f72a40ec519cd843b1c38ebe9ee2be23628961bffc952c1da59c3687a87466Virustotal results 24.14% Quakbot
2023-05-17Sgjd.jsjs 1f26839da60e55672a1ff564cacf4050f50673ab46f7c13ece884b64e8db290en/a Quakbot
2023-05-17Hueymp.jsjs ca99a531b2e34c4f23683a2cf2f4a2e81bcb2cc4975ba287d0bc6ef71563472cn/a Quakbot
2023-05-17Vvviais.jsjs 43a19d17453fa7c2633186d340c06a3b0b794b8cfe7e6ce0adf02f44713c5e25Virustotal results 23.21% Quakbot
2023-05-17Huaqnybc.jsjs 586fe07a69bfe8b72088da7156e3feb75ac24d66ef99584f203b73fe30f08076Virustotal results 28.07% Quakbot
2023-05-17Dvwpp.jsjs a6974773e37cbd56791b75effa167213997aeaaa65d704bd1de8aac6d9dd42ceVirustotal results 30.51% Quakbot
2023-05-17Rvae.jsjs 3a16d7765c95e4f1c085fb18814d67ba3d65e6bf93e38d064ef74c1f9d15ac83n/a Quakbot
2023-05-17Dwjocgbt.jsjs 582d7260d0c9d28291c1a5741818450399bdb826da9dfa44e69657727548f4f6n/a 
2023-05-17Kqwk.jsjs 4a74531558292b7ed5c6a05c560815abdab7ea4e5c2a0404aac0860cf990e379n/a Quakbot
2023-05-17Gpbghs.jsjs 96452e69312abed1f8f92faf745d62464d7575d062b8b4f0be7590d8503ab36bn/a Quakbot
2023-05-17Dpxsntxn.jsjs 2f2f1c787d1c268a236637170531bd93a99006d1430b4ce8e98b0c682c91f498n/a 
2023-05-17Iqksnbwo.jsjs 71bb6530553b0dd6e14eea3c43dbd9931ff083b9dc6ab686ba258a9bd5c513dcn/a Quakbot
2023-05-17Amgm.jsjs eefced7554830d8ac5d05d988cce63cf12b8f3a84da6e4b642be259644564fa4n/a 
2023-05-16Snjnqn.jsjs 72cf54e5e9ac035d06b56306f23a36ec60dadd6b2821d87ef67d15b15339da43n/a Quakbot
2023-05-16Wbgvdo.jsjs f86999d6f8718cc44f25ec5380eb652efb074fd2597e07b7a629065e9429eb44n/a Quakbot
2023-05-16Uglkkz.jsjs c78989b93a86a6c53df6db6c38ec6e4dc0429f755529acdedb054dd88accf322n/a Quakbot
2023-05-16Ubzuibzj.jsjs a62bfa9aee6ab72efe899706c3207d387e8c4ddacde22a91280760610671149bn/a Quakbot