URLhaus Database

You are currently viewing the URLhaus database entry for https://airambulanceaviation.com/aest/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659280
URL: https://airambulanceaviation.com/aest/
URL Status:Offline
Host: airambulanceaviation.com
Date added:2023-06-13 16:33:30 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 16:34:14 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 23 hours, 43 minutes Poor (down since 2023-06-15 16:17:40 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_ED049_Jun_15.zipzip 4af4dc9cfe613cb18a8e535227480b43b371ef5fc597f7a1e501269da27940dcVirustotal results 6.45% 
2023-06-15document_BC473_Jun_15.zipzip 6ae7ae3eccb4a111cce1abc61a09966920f33b2174c0a97c6abe1197b345a172n/a 
2023-06-15document_CE671_Jun_15.zipzip 1efd6b2bc3124c01e1f3d67756f13ea5e4103e6cdb9f02f04caba0a786a85d6cn/a Quakbot
2023-06-15arH87BiqMSyl5X.jsjs 161529cb7c28baee604d4b0212b378951170393b1b8615ece1a6f5c18ee95793n/a Quakbot
2023-06-15Qh0czsuX19YO.jsjs 1b6181b6dd147ad99db2e1885ad3036c8adcf959f550f8d2c9a95511c3641ec4Virustotal results 16.95% Quakbot
2023-06-15h9zJqrLu3l2q.jsjs 388cd65013b5976564554ae9f43203722929a00ad89f857d305178cf7d89d869n/a 
2023-06-15JrmHEiwTWediA.jsjs 6c4463f75044dcb48648e3d6318d1dd1a378101de262a173a54a1adb5ae52e89Virustotal results 0.00% 
2023-06-149tIG0umS96Soe.jsjs 9c233f64dc69e5cc349a403592305a3feeb40af306661f7caa296426a95b659dn/a Quakbot
2023-06-14rpWyaO5P6uqzr.jsjs 4104e3cb0bc4bf60e7df57f316dcf194eb384597ac86839e6474dfa99c15c141Virustotal results 0.00% Quakbot
2023-06-146O25f5vJ6zGhE3.jsjs 765972b4bb92b6da068e2b9d4d13186adfdb238cabd483a59ee1d46ff7b8627an/a Quakbot
2023-06-14docu_ED903_Jun_14.zipzip eaff849b66598b505ebcd9c93fdaf357952bf9c22d7725cb8974f736d1c8ebb1n/a Quakbot
2023-06-14aZeNnjaQ0TriCw.jsjs 2fa7b2040ac076e3788b317655009f3136cde0771ed829a5b4d18a366aa8956fVirustotal results 0.00%Quakbot
2023-06-14eozfQ66pGEjjz.jsjs 0e00ded5f9ad6662d955770f086ae1ed52d0eaac9375c87f9ca0e2d2ed2145cbVirustotal results 0.00%Quakbot
2023-06-14F586qB18I2jN.jsjs e74b9e82e22583477e942f2e1f99ffe7b954fc91b4d599756ee9fee1b739d4f3Virustotal results 0.00% Quakbot
2023-06-14aQ66Vbd4nPTH.jsjs ddbdf8827c8645e4d3c86f2a770adccaac5370409f0db46031078e56af9d71ebVirustotal results 0.00%
2023-06-14VAVPmIHCNaKTV.jsjs 0975c3c93b7f70c773fb13060f63c8d1435081c5dbd2c9f5a7d1abd4eaebafa8Virustotal results 0.00% Quakbot
2023-06-14S7ZC0B4rK1iA.jsjs b705c3a886481f893789ca4b5c4f7f2dbc6b7b0592dbf947eaaa1fb3f00239f4Virustotal results 0.00% 
2023-06-14Q3GWnvxJLjkGX.jsjs 8b5515174bf8ea47b83827e843a7313b1e6997d67bf879820238bd6538a55c68Virustotal results 1.69% Quakbot
2023-06-14v77dUQiXGQ63m.jsjs 5ad7cf86a6ebcdae9bee515375c90d51e24e26077a5eafe34011f3c9f756a65bVirustotal results 0.00% Quakbot
2023-06-14VW2EYAO9FPBO0r.jsjs 53c1fa6e950d5688bb7ecd26f397579a37fcfb28d12869a0b7f7c4899a9d6cc8Virustotal results 0.00%Quakbot
2023-06-14u6vxqC81HDYt.jsjs 2c0eb730bf95ed68473c18275de6e8fa29ca3e48e96a78a75ac8b1126fc3d6beVirustotal results 0.00% Quakbot
2023-06-14R6A0y0i9F6qERK.jsjs 643280075b03577256f767d9f5ac21dd0b9e0139def94cbe9313a8323d192151Virustotal results 0.00% 
2023-06-13SQpYg9aMcNQvc.jsjs e918e17a0a639c0f284a76059249a8398b71eb09bb54e4409fe6ae526a332431Virustotal results 0.00%Quakbot
2023-06-13glNkUO81BxIZO.jsjs 2c0314076f91587df56b869725ec51994647a749840e798ee26427017bcd23afVirustotal results 15.25% Quakbot
2023-06-13IWeFpbg2cPCqN5.jsjs 2f3ece6b454cda59647a1b24dd54a71fb05b8c2bda0f67f676e0431f0e6b546dVirustotal results 0.00% 
2023-06-134ngaavsGew9ep.jsjs 9f254a99c8f47a850e92e8198602d17bff5202ad9baa1fe39877c2e36db17d9bVirustotal results 0.00% Quakbot
2023-06-13lgGcGg5QTG4yz.jsjs 8ffeeccdcd140a1b1df61c29ac16daf11921c3d5dcf5d0674987469e6f147317n/a Quakbot
2023-06-135Ma6Pz5ZBEGl.jsjs 89746e03f20213f3ca6a69b03d54b2a2594b12cefeec6aada6048430008b9443n/a Quakbot