URLhaus Database

You are currently viewing the URLhaus database entry for https://nosah.one/aiai/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659398
URL: https://nosah.one/aiai/
URL Status:Offline
Host: nosah.one
Date added:2023-06-13 17:52:29 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 02:49:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 22 hours, 22 minutes Poor (down since 2023-06-15 16:15:44 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BF094_Jun_15.zipzip db93500e44a2684e71d044699c1c5270916723e212ccdb4957d1eacfb41864a8Virustotal results 6.45% Quakbot
2023-06-15document_DC509_Jun_15.zipzip 4215d40540cb530490e0b70feec1d97a1c37e03b8e816f2e3b0f815f1eb963acn/a Quakbot
2023-06-155Mlc1UdLRtOzs.jsjs ea3fd78e2934af8a995496463374cdef10b0fe052309e5370f8ba7b638b1eb34n/a Quakbot
2023-06-15RPOGUQ7f4v5kxR.jsjs b12782232c7f6fe1960b872c3beb4e4fb8be6e8e6484a3dababb12e4dae59884n/a Quakbot
2023-06-15V3Ww5GunFfIl.jsjs 7edbc8d2106e350a859cae6e9e0de259c790a158e43ee255fb76be64e85d9724n/a Quakbot
2023-06-15pgKgnxjhtIuY.jsjs 8b69b2a765d237d79ed128ec38a4e471222e43c528689953c7029423680bd209Virustotal results 0.00% 
2023-06-15luY2tLrCGzj3.jsjs 3543fbf5b817372eb12b4db3de2f415cd4a717edf80d0fad36536e3f7c0dc6c8Virustotal results 0.00% Quakbot
2023-06-141UNhdlOhhOLGy5.jsjs e95bf20a416f547272d525136fdee112307bd8b1bc6036d558a0bb2d97c113f7Virustotal results 15.25% Quakbot
2023-06-14Kb3dY51ajPsR6.jsjs 4a703b68f597ee967183e609f39984ea9198493ebd535d069f8ab458d90b29f9n/a Quakbot
2023-06-14docu_DB704_Jun_14.zipzip f47c875c7ae2f065c1ef73ea596ba1f3d9b876474e5b6fc7e6b91819f11ba990n/a 
2023-06-14docu_AD560_Jun_14.zipzip f13ef56e5c6b044131aeb5b7c669639354624bf367338c1b166d55177fff0390n/a Quakbot
2023-06-14wRfKY3wHdofWd0.jsjs efd9d13ad982dddd3f52e753dbc6306173d53ffec9664190df0b5fa099af0966Virustotal results 0.00% Quakbot
2023-06-14Ftqx5jyw9icLcr.jsjs 8a2dd98512402598992549ff209edc910eca09454686b9c0502d7e883e064509Virustotal results 0.00% Quakbot
2023-06-14ja91Jyk1AdtMKs.jsjs 33cd588c4ebfa4a6ba76143306d7e61cda9250ddba43c215bd05c71dcbe42e3dVirustotal results 15.25% Quakbot
2023-06-14hQ1yZ933jsQWh.jsjs 1931cee49f7e8c236682655e3d81dd703ea9e3566bd3dce49a504331d2d747ffn/a Quakbot
2023-06-14CSK80tlu0HNSK.jsjs 55d3492acd4da04075013f5fba3ab7e4679f3dec7f671a3f0ae21850e76f1ea3Virustotal results 0.00% Quakbot
2023-06-14km7QHDTSaY3UQ.jsjs 6c4e5c92a7cc22610d2799193e299e3699e3aba8c77caa8668c9ac83cf79f8d9Virustotal results 0.00% 
2023-06-14Rinsr3M7Nd0p.jsjs 87c2c690b9a4ccd266848d48dcddec5f21472f30e1684066638c44e7f287e51fVirustotal results 16.95%Quakbot
2023-06-14bK1tUo6KZFoz6P.jsjs 9efdf759a7bfbb48310e66c322b48ff213edac8fbccfa22e67e736ceaa0a79ddVirustotal results 1.69%Quakbot
2023-06-14t2n2ODUHk7Lr.jsjs 10fc5f940ccf6de1541568b1e647577528c326344c22363ac7fb2f97e964afd3Virustotal results 0.00% 
2023-06-14D2NnCNkDS80OD.jsjs 7229a67d0b9de46809d0fbde394a198b54a9d449a20c2ebe7d26f7e695b881e3Virustotal results 15.25% Quakbot
2023-06-13VCS6wRRz5XxZ.jsjs dc380c6947c5f8de2586ab7baf30b36b6a9426932323cb2096af2c5f4e2c344dVirustotal results 15.25%Quakbot
2023-06-13jOVhmbeNbHzck.jsjs 524df894244a701b9825ef6f279a4ba64292f219614dad255858ccd503a896b3n/a Quakbot
2023-06-13SQpYg9aMcNQvc.jsjs e918e17a0a639c0f284a76059249a8398b71eb09bb54e4409fe6ae526a332431Virustotal results 0.00%Quakbot
2023-06-136WgvGbDiwAno.jsjs 6966078593074ed205090b55924c213c5d93a9e4a3c798cab4bebf084ac20161n/a Quakbot
2023-06-13IVGA53E4C8y62.jsjs 2d43a56a449ddc34e368a2de42a57af3fe0a426065e6dd433625d4745b1a6d67n/a Quakbot