URLhaus Database

You are currently viewing the URLhaus database entry for https://lifetransformers.org.ng/oam/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634967
URL: https://lifetransformers.org.ng/oam/?1
URL Status:Offline
Host: lifetransformers.org.ng
Date added:2023-05-16 21:57:11 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:22 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 days, 0 hours, 39 minutes Poor (down since 2023-05-18 22:38:41 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xjwhgzby.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Ubqdwbbp.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Lwhbcu.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Pkvw.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Alvow.jsjs 6be55c4c2824a4cd16aaf9002adae153b6156ce58174febfd162d82dff7ba019n/a Quakbot
2023-05-18Ovxt.jsjs fe6c3afc81fba017285089bb2240464e993b83edbf51755fe47e70d5ce454558Virustotal results 22.64% Quakbot
2023-05-18Bftm.jsjs d10d47cf284bd492bc540726c1d79412cbfdc49504b7a61547934b5152b0590dVirustotal results 25.42% Quakbot
2023-05-18Oxypzv.jsjs f44e30ffb57afcf688c00896ca7384786ee3ede05210094b66c6d9d6c83675e9Virustotal results 18.52% Quakbot
2023-05-18Wbhhfeor.jsjs 9c3ce9878a22fffcee6c677d536eef828546dc7592693cd8be968e6235ceb49fn/a Quakbot
2023-05-18Iyoi.jsjs 813efe88246132a445789b21b1536bd94263cd9a8c7623d7b96a9e5ac755d470Virustotal results 31.03% Quakbot
2023-05-18Bfltpte.jsjs 229271acfd7face73c4919f8ae74ec7e9e3d276810827e045c7ee12baf2e75bfVirustotal results 30.51% 
2023-05-18Arwxq.jsjs cc1399eba326d79dc397363937989a81822144dc05e184cd6d904bbf2617e9f7Virustotal results 22.41% Quakbot
2023-05-17Yanwx.jsjs e7958ccd8a002219ae5c0a15fe85c42f33e3433270f0ba102d597f19a494e2e8Virustotal results 27.12% 
2023-05-17Rscgaohm.jsjs 294b64c51f30b3884a2067b27a59ddcf4f5c3284a38a7260148eca0e86061a53Virustotal results 25.42% 
2023-05-17Ekthp.jsjs fbf34d1f59eea01ae0ec44fb3d7e93d4a06dad0b411065a5d6292f3ebe7081acn/a Quakbot
2023-05-17Rsdbowa.jsjs d3c173c2dfa25e646847bc107890d76906c807bf85968b5dd9e96044a7729b2fn/a Quakbot
2023-05-17Cdijucpn.jsjs 654d79d5b714216fcec5efd06082250b58afb76155c0be229ba139acd68d0797Virustotal results 25.86% 
2023-05-17Bgrtx.jsjs e29a41a9d60625c8b7ab2e66896cd279af26a9abe095095e8f71d39a518717dbn/a 
2023-05-17Vasiyd.jsjs 1f3d3d34fcd02bfbd9eba7becc4eb01342dffb209af4971f9df25374411cd1a7n/a Quakbot
2023-05-17Zzmpgu.jsjs ccdc371fa95a2dc8192ecf73826f489942857addced0e8ce4b9aa969aa98381en/a Quakbot
2023-05-17Ncihiiw.jsjs 563582c98383772f8817511c5d428868c31158498f2b518b1402fbaf28e354f2n/a Quakbot
2023-05-17Kzvrtg.jsjs 7c5e2cc9568e17a9d95e90b9463362c586580e95b7ca57faf2ada230094bd9d4n/a 
2023-05-17Uoeonjy.jsjs 45fa6e6072753191a0281a385a413589cc04f991932743ef87ebb32b24970de5n/a Quakbot
2023-05-17Qykeqvme.jsjs 135072bc6061836c44f0034d4f23e40d9c4653e13a70cba3bbddb238940b2eecn/a 
2023-05-17Jelinq.jsjs 9d2fbd6a985b7bb0b9b9dc3cbcf7aceda8b16126bcedfb189e29bf187c6779c8n/a 
2023-05-17Czagw.jsjs 5a92b184de515b7cd89342d6c5a1f0466299a5c3817cef0339da34b8fb5797aan/a Quakbot
2023-05-16Ddwzwbs.jsjs fa0e4bb108f7688c696b862cdfebd852c9b62d4a08b95028e88e0aa9abb2a28an/a 
2023-05-16Skehlk.jsjs 09f74e0868a6627cfc05107c46cbdf6741f7a80137703419324fbd2109e6be4bn/a