URLhaus Database

You are currently viewing the URLhaus database entry for https://9null.com/msea/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635671
URL: https://9null.com/msea/?1
URL Status:Offline
Host: 9null.com
Date added:2023-05-17 13:06:17 UTC
Last online:2023-05-18 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:08 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:19 hours, 7 minutes Good (down since 2023-05-18 08:16:21 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Xilkdpv.jsjs 0259d5d40b143ebaaf60af05f38a325f660c922eb6201a18e664d949c3be13a3n/a Quakbot
2023-05-18Piyasz.jsjs 19f01a32bff6fe9b165ef850e438aa1e9f6ca0de31dcfa4ad489b61367cab1e2Virustotal results 25.42% 
2023-05-18Uxlouk.jsjs c56be3ec9c7d01ede485ea9edabc332ef3aa01f6ab679c4eb6231e1db79db675Virustotal results 23.73% Quakbot
2023-05-18Aefja.jsjs ce5efda576bdfd577cb85bba27c1785787f37d30869878530f7249504d45cf69n/a Quakbot
2023-05-18Rbgnjmg.jsjs 47f14a8b9c04f43e700eff818ff6490f28ae0bcba08118d1af9f0b06c96779a1Virustotal results 29.31% 
2023-05-17Cgdpne.jsjs 95f993cc876a8c3aa072647ab634b4ef2df037d739e781cb6f6b4e90ae5d6889Virustotal results 25.86% Quakbot
2023-05-17Yyfvlj.jsjs 8e13d078cc5a623e77df862498a637bd089487d45c2af8d1413f79f59d94dea3n/a Quakbot
2023-05-17Abda.jsjs f37d3c915b896922eed07327ecc8b944fcab1445d20c02c26c5aab8d91473b45Virustotal results 25.86%Quakbot
2023-05-17Zqzqyp.jsjs 043c810fd7d77672928841fc44891531ce536c6b4cfb9a4e54529c20b36eecd2Virustotal results 30.51% 
2023-05-17Pypjsagc.jsjs bbea073ee85951ed23e95e826bbf93fe5f1cd1885d0b88476ba2cd5a1e6bcedcn/a Quakbot
2023-05-17Uhwrr.jsjs 7b0e64b5b88495d402a11b16ad7776cc5e0d44a07992e8b9cf9c7006a92ac8bcn/a Quakbot