URLhaus Database

You are currently viewing the URLhaus database entry for https://book4noon.com/dlul/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635651
URL: https://book4noon.com/dlul/?1
URL Status:Offline
Host: book4noon.com
Date added:2023-05-17 13:06:13 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:47 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 days, 8 hours, 39 minutes Poor (down since 2023-05-19 21:47:58 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Kdosw.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-18Cqkibv.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Vuttb.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Avbjmt.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Cdyayopy.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 24.56% 
2023-05-18Qbgfif.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Adyq.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182en/a 
2023-05-18Dvmwqd.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021an/a 
2023-05-18Cgdjtay.jsjs a18a3c0e37cfc92a00d139f4aebd7996690f4428dea318f028570bf9037d8aban/a 
2023-05-18Pofxxaym.jsjs f51bc0d7dd86e4e6db698538eca1063e4e4936ee3f57c669e347f143576749d9Virustotal results 30.51% Quakbot
2023-05-18Xflbqqj.jsjs 831bcd763103748a036135443a32ea80a8d0c311ba22872149bffc13eec6efc9Virustotal results 30.51% Quakbot
2023-05-18Nvhkelwe.jsjs 614b789451a47511f7b28865dc84ac5a5214ce91e53b5f9ebf50cc64c5cff4d0Virustotal results 25.42% Quakbot
2023-05-18Fwhm.jsjs 534fb18b08176440d03086ec406d8a79bdfaf1488c044a8355d161fd7e521950Virustotal results 25.42% Quakbot
2023-05-18Hlmknc.jsjs c408bd9762412a5776d177862b5ac082170428db1332d9ba6c28929b506a4858Virustotal results 33.90% 
2023-05-18Yyvkgtr.jsjs ca99a531b2e34c4f23683a2cf2f4a2e81bcb2cc4975ba287d0bc6ef71563472cn/a Quakbot
2023-05-18Ufxds.jsjs 17da932080db984c8594c50184bd0cfde690ed29cc7cd73f3136474e2cae191cVirustotal results 32.20% Quakbot
2023-05-17Ovvzelpq.jsjs 3b367e99561731587beb5622ae151a88c15c2153723768a743a9b7f635cf1303Virustotal results 30.51% Quakbot
2023-05-17Ppvlrj.jsjs 719ff669cd7b0754e787346601124ede6c1238c49809ebd0d6b58a3bf4b5a9bcn/a Quakbot
2023-05-17Epwdj.jsjs 3f5e5c65bd5814cdaf300e4fff7de23851e1c5fcc764d920ba42761515bc506an/a Quakbot
2023-05-17Aosew.jsjs 7e29b555dd10291e663446073640ea5519a3e38a3655264511bf14299c86dccbVirustotal results 24.14% Quakbot
2023-05-17Pcwfd.jsjs ca0444007c6c56cf207e9de8f069644d774953d9bc532784f55d5deebc62acbfVirustotal results 26.67% Quakbot
2023-05-17Syjp.jsjs f37d3c915b896922eed07327ecc8b944fcab1445d20c02c26c5aab8d91473b45n/aQuakbot