URLhaus Database

You are currently viewing the URLhaus database entry for https://gdpakistan.org/ao/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635702
URL: https://gdpakistan.org/ao/?1
URL Status:Offline
Host: gdpakistan.org
Date added:2023-05-17 13:06:21 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:09:33 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 8 hours, 46 minutes Poor (down since 2023-05-19 21:55:58 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Nxlu.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 25.42% 
2023-05-19Mvkhjafc.jsjs 6016f12710a18923ed029eb1dc62882b5f1a032a7424e0169dd8c2228598f59dVirustotal results 27.12% 
2023-05-19Rdzv.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-19Abpgxwhf.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Zbohh.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Zqwmla.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Pelyky.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Ncsgwwn.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Ocrvecq.jsjs 14896621b95370a8bcfc6afe61d3dbe752ae6053f6efdf427707c2e9435458d5n/a 
2023-05-18Ktvntzjm.jsjs 4ec189841fea600476bff49f643d0877dcdc3e3050e54e56abc5a7c492ed00dbn/a Quakbot
2023-05-18Uveja.jsjs 2b2ddaf766a72a62c3247e520317d64f6b32231d8802b99b861cdbcd872a7ef0Virustotal results 27.12% Quakbot
2023-05-18Dnncbxwd.jsjs 2dba215a58d9e94365ddf7dad401aaefe0258795b13308a0521c655fc8cbbb26Virustotal results 15.52% Quakbot
2023-05-18Stuan.jsjs 6637cd86cb6d1780d474d49c347f8accc08a24f73ec7d212ecaa591e370d7e1dn/a 
2023-05-18Puvgt.jsjs 93bba231e08381a78fea4f6623a38ef11130273ca9bad59f5132b68797d90d23n/a Quakbot
2023-05-18Mqwf.jsjs 5ed8c2a8ffd44a6f80d52c65210bcb3ab9bbfc42a217a03db9d435fe66f68833Virustotal results 25.42% Quakbot
2023-05-18Xoyflwha.jsjs f3f5b182d275d4c04caa73e7abc7c40748f810123832c294c35b3b4bf997ea3eVirustotal results 27.12% 
2023-05-18Yurw.jsjs fcd00b353c980d48983a4a2533eb482d632935a343b2034ea119d3a4a74f3841Virustotal results 27.12% Quakbot
2023-05-18Bjdofkb.jsjs 783e0a457afb1237e0956e6ff847bfcdb49ee23036f51b4621b534f54d67112cn/a Quakbot
2023-05-17Gmgzrxo.jsjs 2072042cbdf8458366261756217da566a1b8d6cf4b24541a37d71c44c07c7fdeVirustotal results 24.14% Quakbot
2023-05-17Yzprac.jsjs f74f3f66b468e91f7060adfeff51f084fd09fb44b5d93a66ce1b2cccdd016bdcVirustotal results 25.42% Quakbot
2023-05-17Jtknzs.jsjs 91f2349ddffafc85ec07721077d9d38a2ab0376beaf588950fe98bb16d3218efn/a Quakbot
2023-05-17Plya.jsjs 1d2471f7acbab8882ea6f628275c501f0f81e0aeab5ee16537702bd849e8ba6bn/a Quakbot
2023-05-17Frnfz.jsjs 4a5bb0d1af42aabd643a23c518cbc77c4a2931fab8d180bbad1c0ea815f5954an/a Quakbot
2023-05-17Dciofj.jsjs 15284b1502dbf4c84ff0c772b1ae8788a56987a2e9cda8ba27208e57da59e8a0n/a Quakbot