URLhaus Database

You are currently viewing the URLhaus database entry for https://lyhourgroup.com/ilae/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2646558
URL: https://lyhourgroup.com/ilae/?1
URL Status:Offline
Host: lyhourgroup.com
Date added:2023-05-30 16:51:11 UTC
Last online:2023-05-31 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 16:59:58 UTC to abuse{at}hostgator[dot]com)
Takedown time:23 hours, 28 minutes Good (down since 2023-05-31 16:28:52 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_A134_May_31.zipzip 809900e228f5457c17fbe7abc6337433019fce31368d7d73664052bcf8586036n/a Quakbot
2023-05-31doc_D529_May_31.zipzip b23325d063fcae8452518dea4bf7f91da716b9afe3d0cfe60a77486f916bc702n/a Quakbot
2023-05-31doc_F275_May_30.zipzip 5ed132d4356abc2e1fdcde81bea1cf844c44e7f6c95c65d7a30b75418a743ee8Virustotal results 20.00% Quakbot
2023-05-31doc_E032_May_30.zipzip 458b8eee7a428c5138e9443710ace099989f2bb9e10f3c0c29897ad0f0f57e58Virustotal results 30.00% Quakbot
2023-05-31doc_C345_May_30.zipzip 2499f67b6618fc88e2952771b84815e6248f055aa92a792de19f8c75a492afd6Virustotal results 17.74% Quakbot
2023-05-31doc_A407_May_30.zipzip 4e9b7112460459f5169adc7695aa121a43288424b0388e44b79d1a69c1a77f1eVirustotal results 17.74% Quakbot
2023-05-31doc_C904_May_30.zipzip 9184a33024151da37774a5aac1986ee02c4140c9c7cbe9357121fc0a09007ae6Virustotal results 19.35% Quakbot
2023-05-31doc_E813_May_30.zipzip 75f79dda3ec5136d683cf3f69b75279f1a1a2eecf3257289e62e1700259b04f1Virustotal results 20.00% Quakbot
2023-05-30doc_E784_May_30.zipzip 284bc44fbb7ca4a5addb4f123e7d98bdf108ee2f6e1f7d52739a1dc7814a3a1fVirustotal results 18.75% Quakbot
2023-05-30doc_E481_May_30.zipzip 30e419e34701d4261617cb9bb798b7ca45b73346419a3a0450aa7582357a45e4Virustotal results 17.74% Quakbot
2023-05-30doc_C206_May_30.zipzip 74f8ddc00c421e547de47abecbc1cf3cdc2095a072833f431b9b4d6ad19e7a88Virustotal results 18.97% Quakbot
2023-05-30doc_A490_May_30.zipzip 8098b990c9505c4af2ead971ac49b921a94a9247403ddd97ac8782fa8cef9e23Virustotal results 19.67% Quakbot
2023-05-30doc_A894_May_30.zipzip e75ac669df170ed5efdf4d4653cc1398aa0631310cd318058e888c3b8fd30d78n/a Quakbot