URLhaus Database

You are currently viewing the URLhaus database entry for https://nakamuraeducation.com/cqo/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635004
URL: https://nakamuraeducation.com/cqo/?1
URL Status:Offline
Host: nakamuraeducation.com
Date added:2023-05-16 21:58:11 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:49 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 23 hours, 18 minutes Poor (down since 2023-05-18 21:18:01 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Ssqqlx.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Upamij.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Zkdmtx.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Bstk.jsjs 1f48b02228f57b11fce3bbf89780173fc2dbc4106717531a87bcc391b616e648n/a 
2023-05-18Cyhh.jsjs 42046702c8332860c6d6224d63344bbd919246deac12c67a32bee542c7cde41cVirustotal results 25.86% Quakbot
2023-05-18Lubbc.jsjs 0a976cddfcc0bc1b5776cc8cce0d9d1c9fbddfee4017434169358a45936d3ab5Virustotal results 27.12% Quakbot
2023-05-18Kafsntc.jsjs ff4f21489a82d5367cbd581c4dde86dc238f869b950e07bf20f3928f7e6c7567n/a Quakbot
2023-05-18Otrzv.jsjs 3c4d813af231229cc2b961a17a923de449a9f8d67439dd976effea73360ff766n/a 
2023-05-18Jxudfwvw.jsjs 4de3c0071371884b0a2e8815554e19a2c0d89112e1bd9bc512d30aa306d3f0a9n/a Quakbot
2023-05-18Vorqk.jsjs 64dff88a0434f88beb3fac1ad7fb2945b374f90e6ee2ee7322665681b945e790Virustotal results 30.51% Quakbot
2023-05-18Giuipmtq.jsjs 24c2f222f6f2809f7c5dda15d789a41d9424dfce3714fe71bed9fbb0e077503en/a Quakbot
2023-05-18Ykpnx.jsjs 9f16a38888bf7c130dfc15dff72eda59b2621e7c1048f157a4cf51e9bcb2e280Virustotal results 32.20% Quakbot
2023-05-18Egqxncxl.jsjs 928455b0e6b3a04da2d4fc9cc17de42c52ae2a640937dcbc9a048f76050c138eVirustotal results 28.30% Quakbot
2023-05-17Tglxg.jsjs eac6096d9525ff200431210339d6a028b68233173ae11df47f57222dc631697dVirustotal results 35.59% Quakbot
2023-05-17Aqtpbocu.jsjs d7efcadce017eaba7ee055cac3f1fb9842bd54107fb46729f546ede523c09e5an/a Quakbot
2023-05-17Dlax.jsjs 8c4f0c45a34f4cd509c3354346e0db29fbbe4bd099e2b67de6abc88dde35081an/a 
2023-05-17Ueimr.jsjs a45416e3d9aa47760feeee7375be42c3748b04b0d9c6c573bf4db2cfa07929b5n/a 
2023-05-17Heqmmrnu.jsjs 9fc93269f064d50db15333e3dbcf15dccb35094dc51bedfc465ba99ce6a37953n/a Quakbot
2023-05-17Bwow.jsjs 9b57a0a1ea9fbea6fc63b1a41a52f5dc8e9fa5facdff20d031096a0075e9c715n/a Quakbot
2023-05-17Hbnagqf.jsjs 9ac768cf3025869132bdb78aad3f4505cd8dd7e5ddc218e64d6645ba8db5e4f4n/a GuLoader
2023-05-17Vnqp.jsjs e9fe48029049557927c5a03da90253ae3132617ff6a708b6797e7f25c82cabf3n/a Quakbot
2023-05-17Drjbfco.jsjs 8892d626ae4e9509e5d44310c2856c7b6d7be8f15dcc6dd22c0b7d695253410fn/a Quakbot
2023-05-17Kamcj.jsjs 8474e5a9f9800164dd31d4c143d20d5dd2221e9faa2a591548b1b45c3a3cbe67n/a 
2023-05-17Aybeo.jsjs b2177b288e9871e9efe09a556958ecb6b2d2d5b76f7a686f472b66676dfaf0d3n/a Quakbot
2023-05-17Tgsrsbuw.jsjs 8215210efcf2e9ae690b6e4bdc82d7dd4182e0496e9989efe663a356611c09a6n/a Quakbot
2023-05-17Vkqxi.jsjs 99e63bcedba205886b869d2d651496d170e539630e77219d57c17ab4ee4fda57n/a Quakbot
2023-05-16Wxipj.jsjs 520183860e41d2d343dbaac030b29058880d2ab7efaaa076597433393c006a35n/a Quakbot
2023-05-16Ltufux.jsjs 64bdf833b71261a6135373f640a71a8ce7a9e3944d24f805f0dec69ec8952612n/a