URLhaus Database

You are currently viewing the URLhaus database entry for https://aradin.ng/cdi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659410
URL: https://aradin.ng/cdi/
URL Status:Offline
Host: aradin.ng
Date added:2023-06-13 17:52:32 UTC
Last online:2023-06-15 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:54:32 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 day, 20 hours, 44 minutes Poor (down since 2023-06-15 14:38:58 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BF527_Jun_15.zipzip e5dce1eb0d47fd6df8823182d57122f7e61e65e8746e94639eaafd2ab54f610en/a Quakbot
2023-06-15847rIYAzaLzf.jsjs ecfa2f4a4aec3872ca2006986b31c1c931e41cf6b0c2732fe158200a60e884e7n/a 
2023-06-154kLYnSYjkaj6G.jsjs 82313ade9759830bef7315f3c769957810ce78654f47e8fe118a7c25de2bdb3fVirustotal results 0.00% Quakbot
2023-06-14wbSPYbY9vYjZ.jsjs 14d5f7e51e721a63d6911a68bfbb6d257485bb56e1715381906d1b410860cba0n/a Quakbot
2023-06-14jKhacpmOonax.jsjs 7e3ad7bf2fa97a4409bbd01bb67fe408ec5e6866cf5ca2ad74dae8e9fcf41e23n/a Quakbot
2023-06-14docu_BD203_Jun_14.zipzip 0849a869c12d5315bc0a61c6ad89af946dd5f073189bacb7aaf22597891c7780n/a Quakbot
2023-06-14bPlQp9SLqckqp.jsjs 57569333d65d14b891bb0f583dc302e7e5a7def51435a5a128a06b6782d0e3dbVirustotal results 0.00% Quakbot
2023-06-14D4Jo8TU3IuCV.jsjs bbcca37eddd3785374f00e536f7a6ab44b2d0ab8591c7e74dcc25b8409fd72a2Virustotal results 0.00% Quakbot
2023-06-14rmojKhr5DzyE.jsjs 18bc700ae4cb6fcdad8a07ee9a3dac5d23802799aa651e43a4ab31c3074aa69cVirustotal results 0.00% Quakbot
2023-06-14NopY4bIQt2Z7wr.jsjs 6ca765d33ea0eba311be84e9ff67f65dcc4b81c19058c46331d4502dcc91c2e4n/a Quakbot
2023-06-14Kd7c8Mhs9eN4ce.jsjs fc7b2764014269e22e29092384aae3b2087b32ca32619ac2879471b486b19632Virustotal results 1.69% Quakbot
2023-06-149QqtuMZtH5d8z9.jsjs 570a45bb6b33b7a8a0fc9a63a4cc8c50cd2b12923de836ef58cd94c3e60ed5c6Virustotal results 1.69% Quakbot
2023-06-14pHorVf0aOjmf.jsjs efc5079cb78e367de5d06317228a9cbd6960191852d65203978ce7ac42424fe5Virustotal results 15.52% Quakbot
2023-06-14HNd1yYNoxyID.jsjs 412d8ed2b5c5aa3eb0487ca19b47426c2631fbaff5900be52e3c978477d52500Virustotal results 5.08%Quakbot
2023-06-14xuYp0ih0ektsd.jsjs d73ad0f35f7ba862245dfb28c9f3fa54a9bb2b4730302eb8c7e173f97b0ce76aVirustotal results 15.52% Quakbot
2023-06-14MU0WPHrVauMjf.jsjs ce41189c698532d9868b6ca7707a5ef802d8a86a0d0dc917f87877dcc311815bVirustotal results 0.00% Quakbot
2023-06-14rNtvBobPaZqWwU.jsjs eea96900b352686f4027368ea486dc36e9a045408a1d0648815c483533f7c7f2Virustotal results 15.25% 
2023-06-14JhAxqGz5OxLW7.jsjs f666a788127bf2f9889af7487b05343a3bd70aac5e1422f3d072c6c7a2f5f1ebVirustotal results 0.00% Quakbot
2023-06-13JpJEh5qP0QC0n.jsjs d578997e38238c6ced02ce0bb621168c2109002d185e063aaca9acbcac8e42cfVirustotal results 0.00% Quakbot
2023-06-132G5oZwVmC4vBJa.jsjs 50ecc004c17dfdf0cfd97c571e3f51c8e79e0502a93203a3bd86ac7ec51611f6Virustotal results 0.00% Quakbot
2023-06-13Am14dOXdVZNKj8.jsjs 9a5fe07818a395a994f670f3439742df6f38369c1c9130c84c8f3becea552086n/a Quakbot
2023-06-13bJQrQIPQrhCO.jsjs f3c89b57ec700157818293b4ab3cc6998e1cc99bce9e06431180baed8e8f8333n/aQuakbot
2023-06-13JG5BHo4wzSVKz.jsjs 7841a17722296c7ab0cef5982fc317916d62b939bb8b350643eade96ac5ff9abn/a Quakbot