URLhaus Database

You are currently viewing the URLhaus database entry for https://alietihaddevelopers.com/cma/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634734
URL: https://alietihaddevelopers.com/cma/?1
URL Status:Offline
Host: alietihaddevelopers.com
Date added:2023-05-16 21:52:13 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:53:21 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 23 hours, 22 minutes Poor (down since 2023-05-18 21:15:30 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Qydjzffi.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Ampjkzs.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Ikuzgqm.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Llgo.jsjs f396a8f7882b012f85712de9be16f90075b9ac3b1814b1698e8aa5eb080bb63cn/a 
2023-05-18Rbbekqdl.jsjs 134b8da7c15c769cdda57799cf4c8b3e35b0937c9709e7c8e13783183ec10341n/a Quakbot
2023-05-18Jcycbn.jsjs a5ad0d19dd6ae50f16dc5be1921c43a887aba5ab8dae04acbea417a5cd62d61cVirustotal results 26.32% Quakbot
2023-05-18Pxypf.jsjs 7b501e67649c8608b6333e95e174a2d3db77d745651cf4142c43e79b0e1ed927n/a 
2023-05-18Ylfqxf.jsjs 009f072fec4afeeb62ee51fc61e387113eecca3d907b9784a9e4b79ca0c64ddan/a 
2023-05-18Zmnfnll.jsjs fd0ca1aeb929c31a64a1ec9c5027c0c2c644161a6fe7faacf6ea8ec30ca8806an/a Quakbot
2023-05-18Eqqpr.jsjs 02736e3801e700601d6212804b2d824ae4771d32fb369044887fdc9f2076ddfdn/a 
2023-05-18Whaoj.jsjs 7fdeda1296a36cffb37a03dca1e25125b27333e53ead2391247d2790dffd0e7aVirustotal results 32.20% Quakbot
2023-05-18Utjxv.jsjs 37dfc4f0a00904e349fd56b330748fba27b43ebad14ce22ba20df17809091c27n/a 
2023-05-18Yohspjqr.jsjs e50fb972f8f78042286895b6d869daf014f5e8082e3c3989ca853daee780a6aan/a Quakbot
2023-05-17Decguh.jsjs 7f1024ee7a57ad586eb6a36dbb25ba4f7e78cbd55b3c87d5209716b7628bc53cVirustotal results 28.81% Quakbot
2023-05-17Ituwn.jsjs 3a16d7765c95e4f1c085fb18814d67ba3d65e6bf93e38d064ef74c1f9d15ac83n/a Quakbot
2023-05-17Txcnfk.jsjs a74b08fd8574636c900a77d9d50f0c7d91b058b6a82d501d33a366e1e7c3d343Virustotal results 25.42% Quakbot
2023-05-17Lkozdntb.jsjs a6974773e37cbd56791b75effa167213997aeaaa65d704bd1de8aac6d9dd42ceVirustotal results 30.51% Quakbot
2023-05-17Nvtdfxeg.jsjs 494e69eca209ceb575b3ad74ff164605bc99c57a7621108280f95412b64e0becn/a Quakbot
2023-05-17Geswwjuj.jsjs b267e2261f79527d447d6a639751fcabcf68f9640e62a3c3106b4f750cb07b66Virustotal results 32.76% Quakbot
2023-05-17Uwdgicq.jsjs 16c00ed1c4eea2fca24d5ac64106a0261dfc36eb8ff64471f024d0f95efd140an/a Quakbot
2023-05-17Ogvyqlvu.jsjs a0bfb96b1899400fe53e5659dd7edc720f6919eff12171f9ebb2c29b44970b41n/a Quakbot
2023-05-17Suntwiik.jsjs a48fb61ecf74d548a5f945853a1af11dc914ca4fa0fcf79d4d68460621d00dfcn/a Quakbot
2023-05-17Owpn.jsjs aefc039030abb1d413868b29f1f5ac072230a4b156369d185520064cc596e014n/a Quakbot
2023-05-17Pxdetr.jsjs 837ef550cced200fba699adbfbe5d25b2c6f3c8a485204736ba03f353c04fabbn/a 
2023-05-17Sqdplrw.jsjs 9a2bb3dfae42baf07c43ee9adb0447cbb0c14e0a5ecdca89542146dbb64abb4cn/a Quakbot
2023-05-17Vqzpz.jsjs 6e1dcb24868a8d058904fa400e6c8a25180c90b3dc41e95fc2479e7be9c4ee10n/a Quakbot
2023-05-16Rhgqle.jsjs d378cb7625280f86fec1d70e2ac5870de078f752b21c74216b64ef7484885344n/a Quakbot
2023-05-16Bvslwxiy.jsjs 71351a0c120dfc361b8493f30099c82ae9579ab7636049ad0fb8e806973ee48an/a Quakbot