URLhaus Database

You are currently viewing the URLhaus database entry for https://book4noon.com/re/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2667466
URL: https://book4noon.com/re/?1
URL Status:Offline
Host: book4noon.com
Date added:2023-06-20 11:55:19 UTC
Last online:2023-06-22 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-21 04:40:09 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 day, 16 hours, 56 minutes Poor (down since 2023-06-22 21:36:40 UTC)
Tags:BB33 geofenced js Qakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-22Dlcg.jsjs a2e5feea2f83d50f05899a58cbeec2ef6714319b2d34fcb8e83d096b671e9d24Virustotal results 5.08% 
2023-06-22Dkw.jsjs 78f407d5b4d019bb43f9221085764c5a3b2389e1d0ab07c1d470b84b17cb36edVirustotal results 5.17% 
2023-06-22Qqczj.jsjs 0d61164f3a330cdea3b208cf20bfb48e58a556fd16bcbaf9640a569c4b9ff8ffVirustotal results 8.47% 
2023-06-22Murf.jsjs 714a675560ef948aaefda229bc8b181147ca64e9a9e943ee37433683d96e2d0aVirustotal results 5.08% 
2023-06-22Gv.jsjs 899adbf98af78e223e21a3b9c5e8a297ee5cf17d113492bd35eb49c43469f35cVirustotal results 5.08% 
2023-06-22Hfd.jsjs 26fe755ac1ace0f8c9f5363a3c6e2cf7c443cf594d94c7ccfa71dfb3bd405fd9Virustotal results 5.08% 
2023-06-22Qyb.jsjs e014e683809c10a8118698eccb0eb5ecd3232700238a04103954846de9fc77beVirustotal results 1.69% 
2023-06-22Hwa.jsjs 3331d107144cc7679c23ec15d4615d5d6fe6db3efce2f2abdff1567144134877Virustotal results 1.69% 
2023-06-22Aqdrd.jsjs 0af0c9e9a421a76fcb652a4bdb3a7dafe40e9049c00802df2788596ac3209791Virustotal results 5.17% 
2023-06-22Cxa.jsjs 2036d502e09fc1088d047ced4a7408b328aa6810c433f3613b990e8b4fce277dVirustotal results 1.69% 
2023-06-22Jqzb.jsjs 7cd206ef80766b615d29cc720270f56eb601f5645de463818ff019d6dceb5195Virustotal results 5.17% 
2023-06-22Eid.jsjs aa8e72981f1f555f47e8b0022dab4f86ce35eccb4015b9066ab992e48e76ea85Virustotal results 5.08% 
2023-06-22Yw.jsjs b3b85f9c90194c1c7778cc4ea665db7481d1f1c29b9f68ecfb65c1a832ae692cVirustotal results 1.69% 
2023-06-22Cw.jsjs d0d443c7241fe9197239f6503c6142409eb27df247b004bb85d979de9be2e590Virustotal results 5.08% 
2023-06-22Gjxgx.jsjs d96d46c0b3f3387b2b3013e8baf96f2a6108b9a7af1ece6f5e9392a688d01218Virustotal results 6.90% 
2023-06-22Nte.jsjs 6ce9fa360d9f8ad29d803117080fed8c4885f6ff757291adac5b54746d540a1bVirustotal results 1.69% 
2023-06-22Xgbrn.jsjs 612799d36dcc8df6d744e009a73deb930b00b615280281315fb2f1d9cf776897Virustotal results 5.08% 
2023-06-22Tlxhk.jsjs 9ce680e156e77a4dbada3226362d9852a5685024e330701a777533f5033b9becVirustotal results 6.78% 
2023-06-22Dpe.jsjs c3b05c561e2476182c4779fd82256aa8fa3ca95a55bf91fd242a0200f0f98e36Virustotal results 1.69% 
2023-06-22Eoyb.jsjs 94f5dafec18102dc450075a39dd738cc2d43e987f54f40471355f2aef674d85aVirustotal results 1.69% 
2023-06-22Qcrn.jsjs bd027a22aed6e114d097c6c6f5d51f44bd263502af8f0c1254c103ccf160c808n/a 
2023-06-21Jrxvd.jsjs 7328b8c051607428e384e816a74b0eb95dae4d8d867f1c4e3079bb7beb6a97e8Virustotal results 1.69% 
2023-06-21Qrg.jsjs 16985827cf4a825c6a9432cdda408f43c093da3e5ff669fc544c1664ac219fa2n/a 
2023-06-21Pd.jsjs adca9574b8a6c28dcc1468873d9e729188ef9c771e009d88ce70f2b478fe1b83n/a