URLhaus Database

You are currently viewing the URLhaus database entry for https://festarrangor.no/puti/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659465
URL: https://festarrangor.no/puti/
URL Status:Offline
Host: festarrangor.no
Date added:2023-06-13 17:52:51 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:55:32 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 22 hours, 8 minutes Poor (down since 2023-06-15 16:04:15 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BF978_Jun_15.zipzip d59894c4858fc4b13741f0f2e9c27137618f12a9bfff9319ad19b48a7b58903dn/a Quakbot
2023-06-15document_EB158_Jun_15.zipzip 023f9508f9cfebee4cb38a6d451a9aa6810bb364ec96ed227967ef80a6f5c83an/a Quakbot
2023-06-15rh0aZHXmDyjOam.jsjs 146df7add64868453fbfb8f07ca65cdd0858c9507f689036f9e289d59c1c8fdcn/a 
2023-06-15EgdncOCYfd7an.jsjs 95a43d8721d1e2c519484b8308cf6bf73804f3bdb84dcc45aa26c79807bba6b6Virustotal results 15.52% Quakbot
2023-06-15IHpTx7JtN5tQ.jsjs 2f08ef56db68acd2ecbadfb49c14c3d3b73b3054019e008ff227e9978ccc4d4bn/a Quakbot
2023-06-150y4QYCJLGqSLr.jsjs a4da2824b01b9523f1d367056418d63d7e79cb78e13affae66c0a20ecfc40abaVirustotal results 18.97% Quakbot
2023-06-15hsU7WUE7RuOZ.jsjs e36fbc2c2a979d01564c2f002afd203b988742b2b1772f016170d4f4385db561Virustotal results 22.03% Quakbot
2023-06-14WBhpjeEfGfQKP.jsjs 678bf2c911ed752eed903218f41230eff5c83d240c2ad80c454612f27597d805Virustotal results 15.25% 
2023-06-14x7jaL3y6IzhL.jsjs c30dfc71422e3d4a1ffd1e4d708dd497998a7d161c8f3c638581b76edcd5a2ccn/a Quakbot
2023-06-14docu_BA510_Jun_14.zipzip 552bba71721d91a9d865d5989ae66547d4968c1f6fe2abb256e54e9596b91877Virustotal results 1.61% Quakbot
2023-06-146yzDh60oGUd4.jsjs 3f7c3cf5e431d53ca0ec77bb09724c5a82423f23c9a5c181bb4f1913bd11ae14Virustotal results 1.69% Quakbot
2023-06-14mu1UrjtD8Wp0.jsjs 102720722d9553626469767fa53c0f086b2f689942b7eac361205a46d108db49Virustotal results 1.75% Quakbot
2023-06-14IWeFpbg2cPCqN5.jsjs 2f3ece6b454cda59647a1b24dd54a71fb05b8c2bda0f67f676e0431f0e6b546dVirustotal results 0.00% 
2023-06-14aymRhNHRHLW6I.jsjs 65e6c60a3aa0274afa3e7efeae1bbe3265cd6cae71dea184c7c601833b4ace88Virustotal results 0.00% Quakbot
2023-06-14xNqqQkfYnlavf.jsjs e98179ba26166bab10a3785f30b1a5d43584f92e340546d0a379ca0607157aa0Virustotal results 0.00% 
2023-06-14s8i5RYrSM4bE9.jsjs 850e2992f65152ff4f739bdb99220a72c134c80398fa509bc47c7e451e7e43aeVirustotal results 0.00% Quakbot
2023-06-14AgRxfd9qbonc.jsjs d0271301219e188515a222fe550cb20c3c25a8b0fbdf39aeafdc8a6747faa681Virustotal results 15.52% Quakbot
2023-06-14KpvXcQevvMYB0c.jsjs fff98d1cbc657cc9a97e9fb819e8cb4e1bf58d0bab041302d580cc80f919f079Virustotal results 0.00% Quakbot
2023-06-14G03qchyWt68Yi.jsjs af8f3a0dc966d4a3c5f5723c89db6964157a3bed592c471083144a5424b42cb8Virustotal results 1.72% 
2023-06-14bJQrQIPQrhCO.jsjs f3c89b57ec700157818293b4ab3cc6998e1cc99bce9e06431180baed8e8f8333Virustotal results 0.00%Quakbot
2023-06-14TsqTU9pfILynDP.jsjs 0c21520790a4f916213684fcdd904aea5ce48528eb25843c7eafd8c9bd706f3eVirustotal results 0.00%Quakbot
2023-06-14VAVPmIHCNaKTV.jsjs 0975c3c93b7f70c773fb13060f63c8d1435081c5dbd2c9f5a7d1abd4eaebafa8Virustotal results 0.00% Quakbot
2023-06-13FftiCxVfpFmX.jsjs 9f9895cbe88811eb4a244c7ee0b6d3868136a1e1662bdb0202ebdb5930980609Virustotal results 0.00% Quakbot
2023-06-13xrMpMX1caUmHt0.jsjs 972e80b5de0f11fb9129bf2f0ce82681616f9153f9b408337eebab9284e53e5en/a Quakbot
2023-06-13ZcfWDkeld8r85p.jsjs 3ee16b577ee32fab665db753b79031e1de22fd16c928db3f0e5000213409f70an/aQuakbot
2023-06-13Vumyj84I5g7Ui.jsjs ba6ae33aac46c547117046524d4642fde6b2bad02224fdd96966517b808ffd87n/aQuakbot
2023-06-13NmBmdfdsrDm7.jsjs 7c57c6396460e902ae047f35fccfda7d912a5eb5a2fa1fb0a9352aad5a8396c2n/a Quakbot