URLhaus Database

You are currently viewing the URLhaus database entry for https://almarfh.net/nu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635658
URL: https://almarfh.net/nu/?1
URL Status:Offline
Host: almarfh.net
Date added:2023-05-17 13:06:15 UTC
Last online:2023-05-18 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:54 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:20 hours, 26 minutes Good (down since 2023-05-18 09:35:28 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Gssmfqu.jsjs 397ed6d5f113de3b5a638878e1ab22bb58f5fb493aaef92441db571bcb4c81b5n/a 
2023-05-18Dilo.jsjs 3dfefc0e91ce9c601581448bcc12aa145f0ae317f0c3bf6cd09b4605cf679ce0Virustotal results 25.45% 
2023-05-18Igcjhajr.jsjs 185a635c927d918ae74aea58092eb9ecedc06bed0129605f9c210f1a3ad2d63dn/a Quakbot
2023-05-18Kjpdmpqs.jsjs d298331f4833111dff68336933087e322debd03460a21ee0d22d0d8e2b5f7ca1n/a Quakbot
2023-05-18Prwes.jsjs ca42f27ebd7d4d5472c9652e26b5cd7d9f089e838ea85a8ac5f1c51b37e83e30n/a Quakbot
2023-05-18Boypsgm.jsjs f7b76f7e79498990be74945924e01e7f53e3b42e5be51e93dd0c4c7a5ecb47d3Virustotal results 27.12% Quakbot
2023-05-17Mtob.jsjs 8475cb42b6b2c974e37378cf11491570a83f194a37e5ebbc50add4a5677d6d72Virustotal results 25.42% 
2023-05-17Zveofeqf.jsjs 64dbefc6ce8b2caf9b441a36490ebed30319eed28e49ddf95d43659494906f10n/a Quakbot
2023-05-17Zhfs.jsjs b5992b77eea93b7005e9637b010d0dd51ae9310c87bea9dc6eb4610e2826d1ebVirustotal results 24.14% Quakbot
2023-05-17Aerudb.jsjs e1210e09ca90b4d9b1cdd3dd947495e7f1666426a71a9032c997d1abcd93f686Virustotal results 27.12% Quakbot
2023-05-17Hcmkui.jsjs aa29c7434c1bdbe52fd461a295dac0931392a0852902d70bd91693bedfc48375n/a 
2023-05-17Xbkkzzfe.jsjs 962531faf5a4bccd1d88868db9f0b5a79c3073f110ae5e4b9f61d7ea15f8b855n/a Quakbot