URLhaus Database

You are currently viewing the URLhaus database entry for https://bodastuyyo.com/tt/tt.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2598548
URL: https://bodastuyyo.com/tt/tt.php
URL Status:Offline
Host: bodastuyyo.com
Date added:2023-04-05 15:40:19 UTC
Last online:2023-04-08 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-04-05 15:42:13 UTC to abuse{at}dimenoc[dot]com)
Takedown time:2 days, 13 hours, 42 minutes Poor (down since 2023-04-08 05:24:40 UTC)
Tags:755 BB22 geofenced js Qakbot link qbot link Quakbot link TR USA wsf zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-07Aqwi.zipzip 049247a971a9921dec1c5e6f3cdf8fa6e2f59013b32003d24cfd28e22bb59e94n/a 
2023-04-07Xre.zipzip 9074c509f6225c81ce6725d52cf92b04d11980aaefa6bd6e2056118d6ec5bc17Virustotal results 0.00% 
2023-04-06Gvd.zipzip 8eded4e8c1ab42dbcb4b32f8a57a42ca00cea84d08200f837b0db2b8baeadcc2Virustotal results 0.00% 
2023-04-06ZcplO.zipzip 61bb21223710bc3bb8cb2b9f0f97670f56c0bc3d66f422f36be4daf7efa32298n/a 
2023-04-05EhTJA.zipzip 9007076e2cbe71e6470fb78c9eb6ce893ad34f73ca03dd7de888678fbd306449n/a 
2023-04-05Hq.zipzip 3d9932bcfc0dc16adac6d3a5a79f0ba67dbe13a33995ee54e20fe2a53aa368f5n/a