URLhaus Database

You are currently viewing the URLhaus database entry for https://nbstone.co.kr/tis/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660078
URL: https://nbstone.co.kr/tis/
URL Status:Offline
Host: nbstone.co.kr
Date added:2023-06-14 09:02:54 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:05:24 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:1 day, 7 hours, 59 minutes Poor (down since 2023-06-15 17:05:11 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BD725_Jun_15.zipzip f0c537ddc1f79db7368da6a5b8a9cc6bf2a40d830be3685c9c0f77d53d9cf5daVirustotal results 6.45% Quakbot
2023-06-15document_DE632_Jun_15.zipzip 0102a7f330c41711385fcf2f4f60e6762665c4e5957cbc891ea71b2fe23cad85Virustotal results 6.45% Quakbot
2023-06-15document_EA058_Jun_15.zipzip af84f628c724761cc1fcefac2ca292af0fb3df4ddbe5215fec60a63987a223a0n/a Quakbot
2023-06-155QemmxbvwKnxz.jsjs 7b94ce1dfcef7d4cd29e5fce6012b404f88ba3e45ffd23160f14de52ea25bd16Virustotal results 13.56% Quakbot
2023-06-1538NfRk7VPx0z9r.jsjs 9b45256a35b13935112db58d1458688c2cc1fb61377a2cc9b2a76c6662d493c8Virustotal results 15.25% Quakbot
2023-06-15C4js2ToCy8mb.jsjs eb72417abff99c94ca383b47fc093d82f8138b0a501d54d374b6465884b6c4een/a Quakbot
2023-06-15MreXG7ollSEZ.jsjs 8b32fde2c3bee1e0d82b1e938fceb4200c8c92e0ffefcec7d6e934bea1506439Virustotal results 22.03% Quakbot
2023-06-14MVDb157YFzvTiB.jsjs b65994f5b857e035008aa2d377dec6afcd1d2c4fcf860e8bb12ef5c85452800an/a Quakbot
2023-06-14n0WspYxkdDbD.jsjs 0f9701757e68ec0d0ac7c031be3bfaf5e73f8c76065bde54310bde8829427a83n/a Quakbot
2023-06-14docu_DF631_Jun_14.zipzip dfe99e49909839abaa99142b09b1e8eaf4d5ceb9e5880e75b045fc2c805c4f7en/aQuakbot
2023-06-14psXByLdRUb3j.jsjs 5f30d626890f7d044cc7a72b0a2df02b2d1a62c13e427a2ad2922c786283f56eVirustotal results 1.69% Quakbot
2023-06-14W8ybE7RcWZ0pBm.jsjs f45a4d83d31432e7d8b007b102b861265d1c226d9afdb67b758c9374c25b0800Virustotal results 0.00% Quakbot