URLhaus Database

You are currently viewing the URLhaus database entry for https://mywellu.com/noon/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635007
URL: https://mywellu.com/noon/?1
URL Status:Offline
Host: mywellu.com
Date added:2023-05-16 21:58:12 UTC
Last online:2023-05-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:51 UTC to abuse{at}namecheap[dot]com)
Takedown time:1 day, 23 hours, 16 minutes Poor (down since 2023-05-18 21:16:17 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Nllgxcdf.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Cfjhw.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Wsgqccd.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Rwgvc.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 28.81% 
2023-05-18Lzeof.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Xkqn.jsjs bdee1ea589e7d7bfb110811854e69d3f4766185734c3e9309b0fd905ec8814b0n/a 
2023-05-18Yytl.jsjs 9a649ac76d537c5f4ceb023745e2fcb3a6ed8443c46ac1f2dbd7da98f0487deen/a 
2023-05-18Fgixpq.jsjs f9a03e213a2bf36d23d4a6877af8261834b3049ed458410c5e8b4c6da00e2383Virustotal results 27.12% Quakbot
2023-05-18Ghkkeco.jsjs 1bff54d9504766a1b23df7d6c83ffbf3db9ac0d0cc9ded739c34a0f1114f5717Virustotal results 27.12% Quakbot
2023-05-18Wbgyhu.jsjs d4d054686a5e084363a71c69d138897e7b35fe3a4008cdd377ef2a2121799d11n/a Quakbot
2023-05-18Jhkaos.jsjs 256b5693dd43ba9ac782255a11f52251481f5d72c27042d4b6f9bb05aed317f2Virustotal results 24.14% Quakbot
2023-05-18Pauckw.jsjs 683503e1ee6accf36b4e270156fa48982aeb9619157f07c35c1dbbfeb8a43e7dVirustotal results 29.31% Quakbot
2023-05-18Igpjqrz.jsjs 2c91bde6a534aee746616dd47460479f4813dd91fa6b608246e4cbd908aedf83n/a Quakbot
2023-05-18Yfvswk.jsjs 819e1677a9b83e3e2c5f43d5b2dc0f2f54147bd8257c067505fb818330efc68an/a 
2023-05-17Hcol.jsjs 2bcfc438cf9c0a4f72832a134f6709c7596645ff3d738abe3b2fd53250ed50f9Virustotal results 22.41% Quakbot
2023-05-17Yzquas.jsjs a4d5af2c7491cf9e8c6fc213f49572749af1f591ad0e453bfc3770dd17d884dfVirustotal results 17.24% Quakbot
2023-05-17Chxkdjq.jsjs b866fb32a73c9c9a6de4c2fa92651d4d8d7f72f0fe66af797867274e8a889e85n/a Quakbot
2023-05-17Uuloxl.jsjs 8cb9812b4c0409176b2f0770497520692218130496cf0a2a363b4606ce28f506n/a Quakbot
2023-05-17Ofttrafo.jsjs 4bc76e07bcd4d492a60a7464d0a8d6c204b4744fac7ea6748a6b673c6ff31cc5n/a Quakbot
2023-05-17Fiqdxnya.jsjs 644d7490c3fe27e34ffb24eec109bfe9aaaab1a088b489de784de77611e65df8n/a Quakbot
2023-05-17Uyej.jsjs e000b46c0d6abfd08c10602eb092657cdf4c49e578302729b7d31ae55a978a5bn/a 
2023-05-17Iakso.jsjs fd91cd34bc3d37c195175263200fcb27930a605af3d11bb6603a8ebd932b64bcn/a Quakbot
2023-05-17Ouswyxr.jsjs 675a115722dd62b6313dc845a1d118fde7f7872746c89803f6f95f0559177d43n/a Quakbot
2023-05-17Gzyyszxp.jsjs b1def60b4002ef8aab8ff8795f958270c85796082d013bf8ab8b20c376becd17n/a Quakbot
2023-05-17Ocszuqio.jsjs 78b61df168ab3a0e03368fe43d78d84910bd232aa4037dce0543026033e94388n/a 
2023-05-17Vkqcwts.jsjs b9c0be1991cdd8a6e005c8e2fbc199a887126a08707e359d11d0fe512eaa7e92n/a Quakbot
2023-05-17Nuewrab.jsjs d575d1aa951281e07a4ebcd0af9acb5eafd5b8afd1a726a365c5d1cfd61e1052n/a Quakbot
2023-05-16Ysbrowrr.jsjs 35e62974ea1dcc0ae33e721fd71425b35f61cd228d1ee9e684f8c79ebc9392c8n/a Quakbot
2023-05-16Nazyz.jsjs f7930f1f849e440fa65dd3cb4b05131f52e05ea84ff5d508cf4cef0f76457904n/a Quakbot