URLhaus Database

You are currently viewing the URLhaus database entry for https://draleccheng.ca/nso/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659456
URL: https://draleccheng.ca/nso/
URL Status:Offline
Host: draleccheng.ca
Date added:2023-06-13 17:52:48 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:55:22 UTC to abuse{at}hostgator[dot]com,eig-net-team{at}endurance[dot]com,jayanathan[dot]muhunthan{at}endurance[dot]com)
Takedown time:1 day, 21 hours, 51 minutes Poor (down since 2023-06-15 15:46:59 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BF380_Jun_15.zipzip 5d0cc77ffb8e02ae7e8cb5a93170ae1fcf723b562ab572e3246e2d6218ddd060Virustotal results 6.45% Quakbot
2023-06-15document_DB470_Jun_15.zipzip 30668373215a3f73514f170b0a85fcf829a9b5689b8aa552cbf515b0e1a20ff0n/a Quakbot
2023-06-15qGEg5nNd33Jqx.jsjs fa6d61ce06076626393c3dc29eb65f25087d69ed720c70a7d937456ec36399b5n/a Quakbot
2023-06-15E8hDMUq3dWRl.jsjs d851610c49e850e632f0b244d3ab6442ef1aa55324c4a79429ba44f0ae6c52b1n/a 
2023-06-15HJdtAhYWztoH.jsjs 97f2e9710c4670666cb9414d5e64ae8afb01f3d3fbcb474e97500e4ff7c25494n/a 
2023-06-15Qk9R6f7YCIMy.jsjs f81187c07a064af0f0bdce9a2c922a8de29a302cc264bd06c0a66ac64050af2eVirustotal results 3.39% Quakbot
2023-06-14KmNDC0i7QvfuQT.jsjs 935ddc7d61fd41e0485a3888528cccedfe25e895f5caee28bf3685266eaef591n/a Quakbot
2023-06-14R2JG74mf2ft3.jsjs 1c53a7d835164ec09c0bc74a31541220f7dedbc93276e40b18c5c83ebfe6a569n/a Quakbot
2023-06-14ndJCyISih3SZD.jsjs 29f92727541c148d3496af7d78fcd04939b3de1610b7380d772ee1d37b90bc83n/a Quakbot
2023-06-14docu_BE258_Jun_14.zipzip 1c7915036ca3d3b80fd9ce0161914cd9137199aa8b78592661a7a37713c1e70cn/a Quakbot
2023-06-14docu_AB174_Jun_14.zipzip 108c83c7c410f71205ec28be3246d76cb563857407541372717d4891c0488b5an/a 
2023-06-14Y7U0NQroXSikb.jsjs b9ffb402836bd3d588877a6c08f403f6668733547cd631d175d9ff91e19e5516Virustotal results 0.00%Quakbot
2023-06-14DOwnePBYmjpf.jsjs d1d86bc8c4b7b5b439b81526da3587affca593de26bc275b93a7ead4976ef1d1Virustotal results 1.69% Quakbot
2023-06-14auJeZJ1pj73l.jsjs 42a6eb7f0d1787a73977a6db724b2fa7b11c4d500aed1504f2c8531b419c4065Virustotal results 1.75% Quakbot
2023-06-14LBg4jVUTABQX.jsjs 3df0fb465f311f75474fef0685fbf90a438f2fe093eeb89f05a52dc075f16da4Virustotal results 1.69% 
2023-06-14DpwDiRPANBcV.jsjs 733f6d1e5bf6b5bc771d343e71563d881ecc120c46611d6258febdcf169eeab7Virustotal results 0.00% 
2023-06-14rtAadZ3Rq8H0OE.jsjs 52029a2f5051ca1ea16887ce8a453cf92970b3b1b828ef9c388b4e4aed6649bfVirustotal results 0.00% Quakbot
2023-06-1405AYrbzEn6y0y.jsjs f4ab024b24634fbf75d1c9679c7e4d3ac1632cf4554ce6546c75ed77be0b3562Virustotal results 1.69% 
2023-06-14RfIsDFAgCoRK.jsjs f807e330bebf316d856d29a2bca445024022ed98fcc7e8696258545abd99457bVirustotal results 1.69% Quakbot
2023-06-14tpll2uD4Txut.jsjs 28e27ef774938be3a57795a81a35d5b0ae85e7a257c2522b29e16f132a1c3fdbVirustotal results 15.25% Quakbot
2023-06-14V0HdWsxTeHez3.jsjs e43fce049074b91782ec0c826b7ce89402dfed3053e23b15d8472264b63ebbc8Virustotal results 0.00%Quakbot
2023-06-13QuC86XQVHCJ9y.jsjs bf01a7146dfe92bf81f1e4dc18cd8f7bc4d3c66360c344aa8183336483d36f70n/a Quakbot
2023-06-13rjg3Jsr76OFV.jsjs 6da029743607bb22e88cb150fd7747cf0a8668764fb56332ac14509f3cdd6baen/a Quakbot
2023-06-13EvcG4ShDrxie.jsjs c560caa45b825d01ec9bf2dd4eaecbe7e34c80301c4c5ce8bdfacade0f7e3e4fVirustotal results 0.00% Quakbot
2023-06-13nhxO7eoiXu9zQ7.jsjs 31d3d0685be4ee92838a6645510847a3c36241a12760a0d28ecfbca82f5332edn/a Quakbot
2023-06-13N5HWbSLuuyIsLC.jsjs 52bb11ce6f9126bca631c0ba9116d446457e2dd77d29a343e5a300e0e5303b46n/a