URLhaus Database

You are currently viewing the URLhaus database entry for https://zulfiyya.com/lnc/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645633
URL: https://zulfiyya.com/lnc/?1
URL Status:Offline
Host: zulfiyya.com
Date added:2023-05-30 12:09:13 UTC
Last online:2023-05-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 12:11:01 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 9 hours, 28 minutes Poor (down since 2023-05-31 21:39:52 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_A256_May_31.zipzip d4e3b58d8d38e28311e248ab3428ebabad06cef8654af56986b735141deba003Virustotal results 11.11% Quakbot
2023-05-31doc_E813_May_31.zipzip dad75d64ab71b0581fe5dc60e48e871a2168a7c554605e4db77464126f92b3ban/a Quakbot
2023-05-31doc_D854_May_31.zipzip 4a764662c915e06c1fdce232c1a852c85dc3392fd40dbe2d9e62937e25976b74Virustotal results 22.58% Quakbot
2023-05-31doc_C354_May_31.zipzip 6edc0af18a04fe76c85af711144e769f8a8f980b1b741b8dd19c801ee0868b3bn/a Quakbot
2023-05-31doc_B403_May_31.zipzip 4cc58817b2f2165423ae1ed433492da3d8421f691f3b6ab5cdfdb52494e46377n/a Quakbot
2023-05-31doc_C960_May_30.zipzip e80269f7ac8498c418cc77e667728b12209c749bb9274e4462ff681230bd557eVirustotal results 17.74% Quakbot
2023-05-31doc_D695_May_30.zipzip 75b258dd1a1564bcd1df01f37a25407e00938b9ce8bec9a1edc7c1a3968c7039Virustotal results 17.74% Quakbot
2023-05-31doc_A172_May_30.zipzip 1b0ea04ad694d447297bc0def95108df0f0383762e9dce8b339e389932701be9Virustotal results 19.67% Quakbot
2023-05-31doc_A095_May_30.zipzip feecedd121bbcb92afddb472669ab39aa3bd6dd1b2272862638895585d57f8e6Virustotal results 17.86% Quakbot
2023-05-31doc_C175_May_30.zipzip f703b0b6dc5b1647fa385cebf1a04feb1892de8eba1273cb4d16a87093bc5934Virustotal results 20.00% Quakbot
2023-05-31doc_F721_May_30.zipzip d166e570f4cf1583ac3450872649ee8a7d347d2b5843efcf03e1877d6f4721d9Virustotal results 20.00% Quakbot
2023-05-31doc_F510_May_30.zipzip e2c80bf511427f3ac24e5db4a80cc49863a82491bd3bea3c7b62b1333c225025Virustotal results 19.35% Quakbot
2023-05-30doc_A243_May_30.zipzip 425072bfbdf163b38df32af07a856513db792751a91990ffac61fa96e4cb5587Virustotal results 19.35% Quakbot
2023-05-30doc_D138_May_30.zipzip 43d748b524d6815f29a6fc3779a8deeb00fba1ca36ee4917c3c5c4c9ddd1b410n/a Quakbot
2023-05-30doc_F530_May_30.zipzip 981366fdd3a0bfba4056361414d0fb8bbcaf22fa47c79724e948808dc4e185ffn/a Quakbot
2023-05-30Cancellation 512457 May 30.jsjs 1688e1e2bf9819be0d0219f244367874df7c8e06b95aa9543c4a2d753d22a70bn/a 
2023-05-30doc_F418_May_30.zipzip 8b5650ff55fe3efb0059a2ddcf8a9430153654f8b5de8310cf93efa28dacc054n/a Quakbot