URLhaus Database

You are currently viewing the URLhaus database entry for https://ladiesonlytravel.com/gema/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645916
URL: https://ladiesonlytravel.com/gema/?1
URL Status:Offline
Host: ladiesonlytravel.com
Date added:2023-05-30 14:42:09 UTC
Last online:2023-05-31 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 14:43:49 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 3 hours, 17 minutes Poor (down since 2023-05-31 18:01:40 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_B948_May_31.zipzip 2ed4e2ba0b08b0019b5e33da10781e6e26a51091fab7b76d1c073ed91117357bVirustotal results 20.97% Quakbot
2023-05-31doc_B893_May_31.zipzip 4de9e6e4052fc9b6e7cfb13e41da1785b7c4ff6ec9bf5a23c260da95e3caa47fVirustotal results 24.19% Quakbot
2023-05-31doc_A984_May_31.zipzip 01364157beeacbad47ec9591504572ab2a05292ee95fd407b3d6eb733ec7673dn/a Quakbot
2023-05-31doc_E657_May_30.zipzip 8df2ffe7b18e0ba364650e8fdc5197ffb992b5d49ec1a23c96646a856e5615a2Virustotal results 17.74% Quakbot
2023-05-31doc_C469_May_30.zipzip b29ce45faa874ca2ea0086265d533025b64555bec9883b0035c3d8f4bed1ffeaVirustotal results 19.35%Quakbot
2023-05-31doc_C805_May_30.zipzip 4f75dfd421785423fd352fee5332ec84e265d102ba14dca8d05273b046ce883eVirustotal results 19.35% Quakbot
2023-05-31doc_F763_May_30.zipzip f1cc9f86c17f7afd0a8b7f1eb8b25e59fed91690cf5bebfc763ed9ee2a411b8fVirustotal results 19.35% Quakbot
2023-05-31doc_C735_May_30.zipzip 6ed8d8a7faa904b34d4238dbf10371de1c41857e249254c59d9f9e3938211258Virustotal results 17.74% Quakbot
2023-05-31doc_F416_May_30.zipzip ce0db110db0203cc22857de4bf75ecbbca69ee0c50158973815dca70d5398c43Virustotal results 19.35% Quakbot
2023-05-30doc_C725_May_30.zipzip 901214c8fa55fa26023a71ecd1d3cdbcd45821bd49568105df246ac4a663b995Virustotal results 18.03% Quakbot
2023-05-30doc_C981_May_30.zipzip d9771ab82af8866d0390ebfdce2f563f993b36bb67d6b2b051be483c85fd4478Virustotal results 17.74% Quakbot
2023-05-30doc_D423_May_30.zipzip 30caec5b33598196564c4b94cc3583cfff2f642dcc17251cbada0f29db64fb6bn/a Quakbot
2023-05-30Cancellation 614486 May 30.jsjs a903d88c7b6cf5039e2e1b601c13abffc8ef20a4234b940fd9d2f7e963b604ebn/a Quakbot