URLhaus Database

You are currently viewing the URLhaus database entry for https://muslimaid.org.pk/qsip/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659973
URL: https://muslimaid.org.pk/qsip/
URL Status:Offline
Host: muslimaid.org.pk
Date added:2023-06-14 09:02:08 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:03:17 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 6 hours, 4 minutes Poor (down since 2023-06-15 15:07:51 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AD735_Jun_15.zipzip 9d539d829c9bd4b2080036344bf012f1eef3602f4c31169199bdfc7ce893b972n/a Quakbot
2023-06-15Ww1vUEPJuE3qH.jsjs 7151b60c9b6f6f51564c06e2f7933d091bc734d271ee1ea2931a966631605612Virustotal results 13.56% Quakbot
2023-06-15PWjPTa691b07G.jsjs 16530a15411d8a66e7f62070f05673a907906eb2721ee90053b6559e1d3406f6n/a Quakbot
2023-06-15kqS6MkQQCKtNwn.jsjs 55a368cb7eab13e6615539c954e25d58dc5a6e179970b57385f7cd0084256ff8Virustotal results 0.00% Quakbot
2023-06-14DSfEPLLDnzTa.jsjs c3555091c5e7b4f14ca40e5b24ddfc8a319a3bd6ba7f38403fcba18e918060d5n/a Quakbot
2023-06-14docu_AF275_Jun_14.zipzip 591a0c157c1cfdaf3a3a4e1e96882e6ee95d89393efb2147cc3eecfbed486b33n/a Quakbot
2023-06-14docu_AC263_Jun_14.zipzip e24fed82584f4a4e8fbff63d34d0d8a3ffe54476346f989aa3ad5cb111b61135n/a Quakbot
2023-06-14uxRIFAgje21o.jsjs 8670dee51f9e9588f77e0da71d324085bd9f779001244b568f807e6e24782340Virustotal results 15.25% Quakbot
2023-06-14RFAPF4c7ZlcF.jsjs ace7e54ad918b9e0d402b739f428fc4ab0e95c43b528047136339fac1caca828Virustotal results 0.00%Quakbot