URLhaus Database

You are currently viewing the URLhaus database entry for https://lyhourgroup.com/oa/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2629732
URL: https://lyhourgroup.com/oa/
URL Status:Offline
Host: lyhourgroup.com
Date added:2023-05-11 11:58:18 UTC
Last online:2023-05-13 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-11 12:00:07 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 days, 9 hours, 27 minutes Poor (down since 2023-05-13 21:27:45 UTC)
Tags:BB27 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-13Zcujvytb.jsjs c42a5962abd0290ed24ae568a693744e46fb0059521b2b5637e194dd0e5c1f30n/a Quakbot
2023-05-13Iwzwlgpn.jsjs 3bb1013b9717c75f926fb0d270e7e33dc0896d9e82dad214fe6556c43858b5abn/a Quakbot
2023-05-13Tldrv.jsjs 50cdf8b0988a77cd6d08c42bb823190c5854ada42439f83815381c1505bd0cdan/a Quakbot
2023-05-13Fhcvqm.jsjs d92b55823b12a8246afb6252faa691fac1c01f3924c6b80727a8dfe22a4ed78bn/a Quakbot
2023-05-13Grnx.jsjs 7343bdaddfbb2bc4a05f29038ea410f2bdaf168d33d93abc8645c230de9d7aedn/a Quakbot
2023-05-13Haopqcgo.jsjs c4b758175e6525cca4add5e6c1ff5238a9686c31c5f49e8146cb15fe0e6ab059n/a Quakbot
2023-05-13Kshz.jsjs 5211a2abe118f160c7a2263c137a9e7587147c10a4d8f1ca22caac8d6e7fc04bn/a Quakbot
2023-05-13Tcsdl.jsjs 1b7f3a80dec46e3de1b7b9637b3bf14784484e99271a3f28d0455de8707bbd0dn/a Quakbot
2023-05-13Kiglhpjv.jsjs 2b81f8bf120d3d84f808a144b5559c04d2163ecbbbe03a24bf793c3444af1b17n/a Quakbot
2023-05-13Zawi.jsjs 562adeb359f74d0743b1acee13bccfcaf6aafcddbd83bba32b2e1f00294cb3f0n/a 
2023-05-13Swwmm.jsjs 5800468498b8fdf80894c9647c5c57d4b58b1bc362404435c6b2820a160de6fdn/a 
2023-05-13Eilzox.jsjs 37411274b14befd26818bf95ae52c709476c8ccf5480968372b5e9f7151a4756n/a Quakbot
2023-05-12Yqmrmo.jsjs a09bbed37cd27e5ff1b2b8a27cb0b38e1caf744aaa89a4f4143ddc20a48e8e9bn/a Quakbot
2023-05-12Tlhytc.jsjs a939b45ddc7f688fd0392b334ed628bc5ab6f9f622ef4ff8cea20db99978b9ben/a 
2023-05-12Dwrp.jsjs a12057da01c65b6f92fa9316f5cc25a6062215d552b1fc59655c95959dbf9099n/a 
2023-05-12Cfjpdlt.jsjs 12154ecdef2e49ef4283b694bf54e6d0fa7f0bb63c5a2606682f2103275189f9n/a Quakbot
2023-05-12Kkiqsiy.jsjs faf50423a07ff6ea4ea67e8d5056a9e8f565ca95013451f6bf76a9bda7c109d2n/a Quakbot
2023-05-12Tejb.jsjs fcc18610283d068b9d3311054a06e28c88a55d919800b1418975aa92e8d5eef6n/a Quakbot
2023-05-12Ibfi.jsjs 23836194a4de72aa3ad37877665223dfdeb2cf7d1f74c60e4541174b36835f42n/a Quakbot
2023-05-12Kgfegm.jsjs dcae5ff38dc92d999c601a75c2c9de189cdf53053316c87511de78433d6c23f5n/a Quakbot
2023-05-12Zjpx.jsjs 0a4e2216c401eba57616133481a78bd637af3609431a20fa15645fd12b55da83n/a Quakbot
2023-05-12Rngj.jsjs 6d0e50c92fa38223d87fa43e5baf530641c48286ce23ca495756d97be98ef834n/a Quakbot
2023-05-12Mwpzb.jsjs 2e5ff8c0535e403b4db3b1266a30393830d8d1324c03fd6c2d538f71fa7ee096n/a Quakbot
2023-05-12Upizekg.jsjs d552ad659e33654ebe7eab1a7677baa5d3ec384802bd61904f3c3bd15d10c075n/a Quakbot
2023-05-12Ykcr.jsjs 1299081483e7b948512b76f921ef4588e5580bddf752366f2c9b2490657f97c6n/a 
2023-05-12Teycskwt.jsjs b42764e714e11ecc1243e125665ac591002e421c20273d9e5783f2383a4f677en/a Quakbot
2023-05-11Mnqaj.jsjs 903f65efd0e3d4605ef5455d6db15a03b96c168d4d23195f410846745641eb3dn/a Quakbot
2023-05-11Bcney.jsjs e7724a520e893ed2433631c22ec3b280999074319bcd4171cec694384e784ed6n/a 
2023-05-11Wnek.jsjs 51155b4466bcdab285943d93ad159611bcfacaa14e012b885b41deb77c0a145en/a Quakbot
2023-05-11Xrasukcd.jsjs 6e900b3672f2fb76ca277149b5ec15fab913fba76bb0dc167938c77efb69a985n/a Quakbot
2023-05-11Glos.jsjs e3333fb13b1403008448e9579776035c48647ae685b248acdbdc65762d6b2af8n/a Quakbot
2023-05-11Llyom.jsjs e35572ac4ea266f7187673890b48d6d44b119efba677a68580e7b570b8347528n/a Quakbot
2023-05-11Uztlf.jsjs c3409efbebdda10ea7eb98a084f8fa683b661f35023a0580a356489a4cb4b9d7n/a Quakbot
2023-05-11Bdpiy.jsjs 5df9e99a5392e9970c6e280925850ebbd8561a178fcf57575c15aa1da854ecaen/a Quakbot