URLhaus Database

You are currently viewing the URLhaus database entry for https://rishtedar.com/aai/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635063
URL: https://rishtedar.com/aai/?1
URL Status:Offline
Host: rishtedar.com
Date added:2023-05-16 21:59:14 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 22:01:34 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 days, 0 hours, 51 minutes Poor (down since 2023-05-18 22:53:04 UTC)
Tags:BB28 geofenced js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Wugzmm.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Vkkhmbdk.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Omgvtm.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Eumnc.jsjs 129b4f57a86a79d5ac97ed9c01f81977b4858b4a1b6a0f9c7cf6e201b879a5ecn/a 
2023-05-18Agjcbk.jsjs cbc57ebccb343515692b47782246ac3ce19ae8ae335ddc9895810261d11cb663Virustotal results 16.95% Quakbot
2023-05-18Jafafpbs.jsjs 798823d6f774c2380137f2e4d5c8a16ea4cec5e96284dfed0891528bdf512376Virustotal results 25.42% Quakbot
2023-05-18Vtdfac.jsjs c7164e6f2a5f4d34a5877e5de94ba49af13d9b6e10be7158adc9e0d267084c28n/a Quakbot
2023-05-18Effwrqq.jsjs 9f9b7a0d9944437dbf0052fad1d08898979bd6c9a9d937a98cea3c757a5f15d0Virustotal results 27.59% 
2023-05-18Mdimlsi.jsjs f865f1501145c736f9f72ffa6b3431effc20f094261818dfc60ace530d2aacebn/a Quakbot
2023-05-18Pavmta.jsjs 4604c9a02925f680aa68df7691aab5b247d61f74fa2c2c261a58ed40e9680327n/a Quakbot
2023-05-18Eughiqfc.jsjs 37dfc4f0a00904e349fd56b330748fba27b43ebad14ce22ba20df17809091c27n/a 
2023-05-18Xhdjmc.jsjs 813efe88246132a445789b21b1536bd94263cd9a8c7623d7b96a9e5ac755d470Virustotal results 31.03% Quakbot
2023-05-18Xtml.jsjs c97e0d75191c3cd583de9edf9cef56be0b4b4bb3e072a64e3fd6133eef6ea96dVirustotal results 25.86% Quakbot
2023-05-17Mnshpgyi.jsjs 26bcf4ed38ca973b884b3322675bbd0b590533240961f9fd6272fa3e3aeba113Virustotal results 31.03% Quakbot
2023-05-17Pubxewye.jsjs 17dcb0baeee21444da6b254c7dcd1d98989c6a0c089b8d79530a2c2a83dc34d3n/a 
2023-05-17Qveau.jsjs a1353f7898cc49901d6c5dc01063b60be173f0ab2378d18348e3b766cd3a9913Virustotal results 25.42% Quakbot
2023-05-17Ybzmum.jsjs a2fee1f921c59d61590ed86bdd9e19a12b68d9722d228d0e5bef678bd31d461bn/a Quakbot
2023-05-17Grcbutnj.jsjs 24579cbeb7c33196bff853d67ce422776e45c942b057519eb6a6c453ed30ac62n/a 
2023-05-17Nokp.jsjs 1e96a7079b653386193018082948ee18ee1ca517dd96395eb46b4d5e30507b87n/a Quakbot
2023-05-17Icaczrqi.jsjs 6dc62d91b51173d75d4caf0ac48c78c75a38f79146ca0f113ff3c4a77f53ebdcn/a Quakbot
2023-05-17Wpkbqyc.jsjs 4d3f76aaa89ab808c3cdf577b4d43b1a9b26eaf8f8a5468764192a6b4186f4c0n/a Quakbot
2023-05-17Akndse.jsjs 8e29eb916a2c6c74a6a625c7513ea3bdb1810b5bc0568933b45feb6287124639n/a Quakbot
2023-05-17Bskpv.jsjs 1afdbb3106e7e39aadb88449b0b062868cde93ee19e95dba1358411e9dedb690n/a Quakbot
2023-05-17Sjqrce.jsjs 47e1dad21122bb9e44dee0bb8ee929f5546574a3491c70628eba05e58b68186fn/a 
2023-05-17Dozcbbg.jsjs 94eb4969d66a1b0e2148e23abf70a848fbe6b071e7719ba42d246696e20ec024n/a Quakbot
2023-05-17Guudxqh.jsjs ba966494ad449cf31142d7b2b6eb31de2dce9eead56307ddc1f8fb94fb4f2151n/a 
2023-05-16Isiltzx.jsjs 1bb4cde01c1fe024007540fbd3aa6a2effb0b50cb8c5f81dcd4017388a09ae79n/a Quakbot
2023-05-16Zzaveo.jsjs 473897707f3e344da08880a30b9eccfa6edd14a061656e3a0615ea548e0f77edn/a Quakbot