URLhaus Database

You are currently viewing the URLhaus database entry for https://book4noon.com/qtus/? which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2661825
URL: https://book4noon.com/qtus/?
URL Status:Offline
Host: book4noon.com
Date added:2023-06-15 11:03:35 UTC
Last online:2023-06-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-15 11:05:52 UTC to abuse{at}bluehost[dot]com)
Takedown time:6 hours, 24 minutes Good (down since 2023-06-15 17:30:47 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BE089_Jun_15.zipzip bfd271011d65b6e482bac0301a800981d91bf7d397b99414bdd3a49e6740229dVirustotal results 5.08% Quakbot
2023-06-15document_AF495_Jun_15.zipzip 0fd17d80b4051b3d719bc9fa915dd7824e328e2f0946caaa04b278aae67d1755n/a 
2023-06-15YnZZqcr67J5G.jsjs 91ff73f39b7db076154f02b17cefc85baf9384523dd86afeba6df8346ddc9444Virustotal results 15.52% 
2023-06-15El6ERsPRON92o.jsjs 73408d0afbda2cc36e878543a298d6d6ecb77e1292c544288583aa48ef16af9eVirustotal results 13.56% Quakbot
2023-06-15PAExFZAovQBa8.jsjs cd2e43cf08dd4395275266cd91c3af5adcaee3658abdc7543c8ad2e3aae800d7Virustotal results 18.64%