URLhaus Database

You are currently viewing the URLhaus database entry for https://sindesis.com/nlh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659283
URL: https://sindesis.com/nlh/
URL Status:Offline
Host: sindesis.com
Date added:2023-06-13 16:33:36 UTC
Last online:2023-06-14 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 16:34:52 UTC to abuse{at}amazonaws[dot]com)
Takedown time:18 hours, 40 minutes Good (down since 2023-06-14 11:15:03 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-14LuTEqhaKztlUy.jsjs 768c7f7dd8a5c0704094fe92cc77d3d667040c32f88658005ea1730725376bfdVirustotal results 0.00% Quakbot
2023-06-140zE6OpI6T2qCd1.jsjs 3b40253f2d234b474c30291c1a8b73b58b3c4f883741aa2e6b674a96185055ceVirustotal results 1.69% Quakbot
2023-06-14e1JX17pDt8UYTk.jsjs 95dcc193fb525ee98badcd4cef7d491bb44e80d4c770e638021c50615550d05cVirustotal results 0.00% Quakbot
2023-06-14cz3EfRwcgvveH.jsjs 5d8b5d90a7cf253503f2a8169b135b71efce84e4c2cbf5feb7746dd375ef1720Virustotal results 1.75% Quakbot
2023-06-14UQ46xmObp5dJgS.jsjs 9188f52e0786097d39407a4a95da624c737a2482bf2c891f9082d21e61f2e5eaVirustotal results 15.25%Quakbot
2023-06-14PuBz6Yya8NaYb.jsjs 26c06f04308b5fd5720e774eb5a489f56df3f852d5b7159d1f55141d5593bfd8Virustotal results 0.00%
2023-06-14NkjEK3pV0gdSS.jsjs a29e6a9e9c53aa408ad61177a73547ecd467f52cc238367f9ad7f2ad5f5a9313Virustotal results 16.95% Quakbot
2023-06-140XHDcGxBWQ3p.jsjs c0dc43667db75e00b26ab332ef35a82862f8a2ebdee5ec113d7477df9c947c15Virustotal results 0.00% Quakbot
2023-06-14QNK9HOCXH9ZvHr.jsjs 0902182c85d945104b57238311d09f63f6e2118f1fae2481be670d0d72289a5aVirustotal results 16.95% Quakbot
2023-06-14tbzDKn7mRpEE.jsjs 344a1e9b38709ad5b49622515847a46e9097620d10cd2ef55242fb68263b518bn/a 
2023-06-14ERbvdDZCa5dve.jsjs d4daf2d217a0fcf8ff210461b5617f3591082c15dfadeb9c7dace10502243b45Virustotal results 15.25% Quakbot
2023-06-13hm6uUbMpX2pND9.jsjs 83ab13a53b95f51b806b1848e60bfb6058920817d8dd5603f6408435dc3b849dn/aQuakbot
2023-06-138NBpht0CPmrJP.jsjs e67cc251b0099e6448533274e9bbee0b22390af8c47a92bb6c7fd8fbd5725285Virustotal results 0.00% Quakbot
2023-06-13bXbJhzU0MQtjFs.jsjs 95f2521606f82ae3b1a8d0431a422c6b9ebb5c047ce4d8cfd9f1850b80f2cdf9n/a Quakbot
2023-06-13YKGhWCPKleYeu8.jsjs 4e34eb94bc4d4b80cf3a777941e563a8485e25b958e3222f3ce32908b1b6dd1bn/a
2023-06-135OZsddt88kWskJ.jsjs 2f611d2bbed4eccbd77cefc020aa9de246c8d90313f37e8cb63f8048557a23ean/a Quakbot