URLhaus Database

You are currently viewing the URLhaus database entry for https://yarrowenterprise.com/cu/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645697
URL: https://yarrowenterprise.com/cu/?1
URL Status:Offline
Host: yarrowenterprise.com
Date added:2023-05-30 12:09:29 UTC
Last online:2023-05-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 12:11:59 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 9 hours, 25 minutes Poor (down since 2023-05-31 21:37:32 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_C917_May_31.zipzip 2cc1888ced0edc468a0cc6bfbf004fc18df13f7f43e9c247ac4696c3ae0465ecVirustotal results 19.35% Quakbot
2023-05-31doc_F281_May_31.zipzip 8b609722d05a32aab714534308a93dcfae53a2a1b873d8a1bdcf5cea578f5dd6n/a Quakbot
2023-05-31doc_A318_May_31.zipzip 8c23746e97df03566204378abb90677e4f361de721e0888c891286600b984d3fn/a Quakbot
2023-05-31doc_B093_May_31.zipzip aebebd3fcd89d4b0f47094f6331f1e86a2506ce228ffb81d4570c5aa3ae63157Virustotal results 23.73% Quakbot
2023-05-31doc_D032_May_30.zipzip e088b6dc4531cc53f8c5a1828918b13643dc6a5fc1686b62371efd6fdf04dff6Virustotal results 20.97% Quakbot
2023-05-31doc_C413_May_30.zipzip 5ca8c9840cf72649809650b6439efaefd839c960ab31ffba92d79a7acef46831Virustotal results 19.35% Quakbot
2023-05-31doc_A421_May_30.zipzip 0db879fa118176786026ae9f98cb448c37b98e04c8afce8e900010c318ed6b59Virustotal results 19.35% Quakbot
2023-05-31doc_F916_May_30.zipzip 1e1726d3dca939b0a42b294c314e66406ad779ea55a7f423540fee5202f56922Virustotal results 17.74% Quakbot
2023-05-31doc_D298_May_30.zipzip 49e47cc5ba896e6652423d5e158051b83a0d453d5c39c0444b211e3bd03112f0Virustotal results 20.00% Quakbot
2023-05-30doc_B507_May_30.zipzip d221c27df3d433e066eda231831487ed5612673838303e70d1b3b8361471c833Virustotal results 18.03% Quakbot
2023-05-30doc_E017_May_30.zipzip 7b212476d346fc37847c81b6663009459f830019126e181bfd262308c386f002n/a Quakbot
2023-05-30doc_B327_May_30.zipzip eca2ca496a77c2965de4680f2de3716549cf08539753ccc695d057bf341585a0n/a Quakbot
2023-05-30doc_C213_May_30.zipzip f2cc710fc6bb31a749d42a237535e5295fba878212707c64fab808f387cca6c2n/a Quakbot
2023-05-30doc_F846_May_30.zipzip ac6ef694101420364ba7183245f99971ab83576c4186ff3ced5dc1e63040d06an/a Quakbot