URLhaus Database

You are currently viewing the URLhaus database entry for https://jyothichitra.com/anie/ipveitsarrroot which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2319893
URL: https://jyothichitra.com/anie/ipveitsarrroot
URL Status:Offline
Host: jyothichitra.com
Date added:2022-09-28 18:01:49 UTC
Last online:2022-10-14 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-29 16:12:09 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:15 days, 6 hours, 37 minutes Bad (down since 2022-10-14 22:49:20 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-10G2317101301.zipzip dda97c711dd54c00632cc1f1c9b6a05de2bdd49336d4af90245354ee70871392Virustotal results 50.00% Quakbot
2022-10-04Co2945820480.zipzip 3ecd4d1b85b995cbeeb01a22844c462ef5f494b92913338235df33b94f4c069eVirustotal results 5.00% 
2022-10-01aoqMirdeuocsntu2680278806.zipzip 8745180bad1c09a236c9ba5ce29a44abc2dd6d072381cfcf61547c8efb5f92e0n/a 
2022-09-30Aspernaturmaiores3724066246.zipzip 25f41cb4f78f3393877c1ce3ca87f4a0f83747db8fbd05cc52e0db6b2e1dbe92Virustotal results 1.61% 
2022-09-29Gall3901550256.zipzip 3b4d82844f321fff734cc8ed7e1ee603a5d78d4bf0636b0e68794753c14e977en/a