URLhaus Database

You are currently viewing the URLhaus database entry for https://hoystreaming.com/lanu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634903
URL: https://hoystreaming.com/lanu/?1
URL Status:Offline
Host: hoystreaming.com
Date added:2023-05-16 21:56:06 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 21:57:23 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 59 minutes Poor (down since 2023-05-18 22:57:05 UTC)
Tags:BB28 geofenced GuLoader link js Qakbot link qbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Fzfl.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Yzyhlosp.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Rjtslox.jsjs 53135c5a76b5107f70f33a158bd1f93695b5083eeea2d965eee9afc7dee1a829n/a 
2023-05-18Xonvlu.jsjs 3cc62e68f657fa870eabb640cd8e651d4ee69a242db9feadeecdbe6a0435ea99n/a Quakbot
2023-05-18Jdlu.jsjs 85341f4b78166b2b1fe18125caf6a187b8c29c45ce7ef3956530cfd4bd6591e0Virustotal results 8.62% Quakbot
2023-05-18Sxeoqlgq.jsjs 0af9a445f31e51c20a58fad5f35d353da59c49e684bf1db02c436c4d7f7f18a6Virustotal results 27.59% Quakbot
2023-05-18Epcr.jsjs 49636b8d67746ef7da6e75b7b961332aa2ec681c92060c1648c4a9730e0abf7eVirustotal results 22.81% Quakbot
2023-05-18Cpfrhvcy.jsjs 148425d44762a381cbc5cf7c9e0e7fb44d71f7162439e78b219929274f34d19fVirustotal results 25.86% Quakbot
2023-05-18Mcvrzk.jsjs 5ca41989b791311510cc85281b20f28cd72d2554b2a862f47d9a9ac5ba9a70f9Virustotal results 25.00% Quakbot
2023-05-18Dixgqwt.jsjs 5e1581b1da5a05a5baee064cf15334c7199e5808fcb9b16decf62e6cb66940c5Virustotal results 32.20% Quakbot
2023-05-18Bzfkoieh.jsjs 91bf97c2e5d25bf79ff22ef99cccd3bdb7aab412d34521e172610b16562203d8n/a Quakbot
2023-05-17Zlfqyl.jsjs 176082ec2166a938b76477a4d42d940987b38d787c43628c9e17e75057338dc2Virustotal results 10.17% Quakbot
2023-05-17Wwng.jsjs b45fa98328f6170801cd88be88f4ac670f2266e2ed383e78f37fdd5d860dc695Virustotal results 30.51% Quakbot
2023-05-17Jijywowp.jsjs 1e96a7079b653386193018082948ee18ee1ca517dd96395eb46b4d5e30507b87Virustotal results 30.51% Quakbot
2023-05-17Tpam.jsjs 89ddd75a9d671f30070d8ed74468e507a72e5ca5699855296beb959dae2b71b3Virustotal results 11.86% Quakbot
2023-05-17Zbtfv.jsjs c56be3ec9c7d01ede485ea9edabc332ef3aa01f6ab679c4eb6231e1db79db675n/a Quakbot
2023-05-17Xhbotsv.jsjs 568dbf92f0bf53b20857f863e58e7f82287fe96c9dc066c782f5f82c64287a75n/a GuLoader
2023-05-17Fyogz.jsjs 0b8b2630460c4baa473d458c5dfe165acc6e1cd41d684697d22599bce6fcf623n/a Quakbot
2023-05-17Kbxn.jsjs 52fd98d3da82444402a0dee6bce346bc95ecec6916b4c6a55e84ce51fd2f32e7n/a Quakbot
2023-05-17Tvumd.jsjs f1fe02b45816301a140c7574206b02166dc5318476a45e86b29b2dc1a822bfc2n/a Quakbot
2023-05-17Pmdmggns.jsjs 98cf9698cf1ace3fecfe7e6503c7756b02952fd1a562dc45db92efe71e51d06dn/a Quakbot
2023-05-17Lrtpnj.jsjs aa7570b0d4534a0fefe1b6d39f92fa5dea04a546ed185f0104e282ef46c5f0fdn/a Quakbot
2023-05-17Hvusk.jsjs 933f159aa265a4971587132b38cf015947cd9fd7b6ee8986c2bff4b16109cb33n/a Quakbot
2023-05-17Prdmyovd.jsjs f40565b8b2007536620fd2269f7ff6b26344c750070e9d6a469047de3f17d912n/a Quakbot
2023-05-17Rosbnqw.jsjs ce5f25ec26f7dad0aa86a8f7b34eade4fa08f3118f0717fefe92ea7800f1256dn/a Quakbot
2023-05-17Pylkapp.jsjs b1c5144c32b8ca20a324268955f60014c067a6c0c6502f899b64535806df9028n/a Quakbot
2023-05-16Gcuwkj.jsjs d13800430d24f8f8515a3929d376d31315365594aadac202879ba039d2aa64cdn/a Quakbot