URLhaus Database

You are currently viewing the URLhaus database entry for https://overnightvoodoo.com/ee/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635015
URL: https://overnightvoodoo.com/ee/?1
URL Status:Offline
Host: overnightvoodoo.com
Date added:2023-05-16 21:58:15 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:59:53 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 34 minutes Poor (down since 2023-05-18 22:34:33 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Imiqvzdl.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Kwybvlx.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Zntsjey.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Anvlbjb.jsjs 88f1d054be875f8abe5757a24f216a85f431e661af7e147ecf758632606886d2n/a 
2023-05-18Zvrst.jsjs ca9502bdc52560b18884b4483fd8adca417142d736bc92b2039511c11483e4f0n/a 
2023-05-18Yaufmj.jsjs d072c0958caad1a6504236a0de9defd899adf9e6deedeb1cdeba1e72229b29d8Virustotal results 30.51% Quakbot
2023-05-18Ayztip.jsjs 75203d83c417a2bcd9a5298c46ac9c2befe4e75e7e2c40722c7b8f59a2232c98Virustotal results 27.12% Quakbot
2023-05-18Valqezn.jsjs e3086e125c0def5547c4247942eaf8cdeb0e4e581562f9cef5e20b6978761c61Virustotal results 32.76% Quakbot
2023-05-18Uuooz.jsjs 5155a314d6e44ed6eb4d65e80d368d8bcd4e8674e293bce8d712b03395d22f6fVirustotal results 11.86% Quakbot
2023-05-18Zdhc.jsjs 59b0a76ebb16b7e92fd7040cce169d3cd207567b8293852c5bc0d44574f68077n/a Quakbot
2023-05-18Itjycqmf.jsjs 14ce409dfb31225a9aa73965aca14ef09852a03cf69033bf2deac2a816796a31n/a 
2023-05-18Jthhure.jsjs 1f26839da60e55672a1ff564cacf4050f50673ab46f7c13ece884b64e8db290en/a Quakbot
2023-05-17Xwehixw.jsjs 4779dbaf4f01d866b1dd6a2cdeb855c53a82951952ba41e9af73be849bc9116bn/a Quakbot
2023-05-17Zdqspstg.jsjs 0836ece78eb77f4b5ebf101fc5e4317ad5554305bff6466db565f247b93b5928n/a Quakbot
2023-05-17Fhkewtsq.jsjs 90d7044e2b3c6695b8ce4be887d9fedf198e2631c47d77093e427bbdc2ff19fdVirustotal results 29.82% Quakbot
2023-05-17Nglxy.jsjs 3c39de1cdb595f8d1822395bd3cf9c81743a1b303cf7188cf41f49bf8c0005c7Virustotal results 31.03% Quakbot
2023-05-17Euvrlrvg.jsjs 2eaa6ab373b017bafebcf7e8d12609c6c9958b230ee8d4a3e4f96294f5ea826dVirustotal results 32.20% 
2023-05-17Erzaztvv.jsjs 80f6fd82b28ccaacb151e0447865a17ab4711eefd8ab38eb96bff981a7077a9eVirustotal results 28.81% 
2023-05-17Ujgit.jsjs a4d5af2c7491cf9e8c6fc213f49572749af1f591ad0e453bfc3770dd17d884dfVirustotal results 17.24% Quakbot
2023-05-17Tmnvtq.jsjs e5e55c026d33a226eeaecaec0b1f0e887452329d55151ca363f093722745e770n/a Quakbot
2023-05-17Jkthz.jsjs 33ab5ea19800f6717379a1e6bab61d309d4c8b8933b3a11892e5ef6b809573fdn/a Quakbot
2023-05-17Hoym.jsjs 4c57618dd8464da13416ccd9ce5157edad85a37b62cff1dc0343c78b825d8632n/a Quakbot
2023-05-17Nnhwywk.jsjs 5f9fa6e120a99475058b83ff447a88e70a9e2c251c1079b18abaee8e09c9b540n/a Quakbot
2023-05-17Rozw.jsjs eb4b0db9d767708f221980e7075f9163603fe3ef5f8f9f5b70bbd68c0c09ee49n/a Quakbot
2023-05-17Capqm.jsjs c58c21aa8eb543cd755d23281dbfc6684ad5a2f724fc044e8d8af1beb9044a67n/a Quakbot
2023-05-17Tgnxkt.jsjs f011963d62b786a7a6108eee64fdc3280ab2f5d82ae1cdde1d4fb03799040519n/a Quakbot
2023-05-17Rsayxh.jsjs 522a9592ff4f2b03a7d7a8a65d86ba890a1f3455a6294d58d1da5b74dab1a4adn/a Quakbot
2023-05-16Tawzjht.jsjs 1c7755c2113901f1ae5eacb04cd101029b9b021050f332bc27c21aeada7517ben/a