URLhaus Database

You are currently viewing the URLhaus database entry for https://shilhaandara.com/luel/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659307
URL: https://shilhaandara.com/luel/?1
URL Status:Offline
Host: shilhaandara.com
Date added:2023-06-13 16:37:15 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU100132722 created on 2023-06-13 16:38:06 UTC)
Takedown time:1 day, 23 hours, 32 minutes Poor (down since 2023-06-15 16:10:58 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CE029_Jun_15.zipzip 00349ef5de79fe9711928f792d6aa8645575bc0ceeffd197c162d3a6e88f5b7fVirustotal results 8.06% Quakbot
2023-06-15document_AE538_Jun_15.zipzip 5809c2d04c9e23936920d009ddda5c8910afc75bdebc29569eab7f5d10bfbf21n/a Quakbot
2023-06-15ZRJnSpGV25PHrJ.jsjs 67f8a32a80cbca75d0206a50f1a700ee85c7b2b4cd3d42598c8ab70e4c51f454n/a Quakbot
2023-06-15Q4OaucQWd8Gj.jsjs 1eb39b21a7d1106b84bdbfeec5ac023b578c6d48db4f8f138c94a74519cef73cn/a Quakbot
2023-06-151Q5x4IlOQvMNa.jsjs e6c8ecbf03cb07a03dbb2f231b0e0cc8802db7d60da479b49d5012d2353c881fVirustotal results 16.95% Quakbot
2023-06-15HLpRG6AsCKTekS.jsjs 3a43b6c8f01f9509f2314ba0d4237e69190f6b7612dbba93750c8f59bb2329ean/a Quakbot
2023-06-15Et6lTI95pIYYk.jsjs 61bbca2bbabd589e27651cdb081dabffd83f36c367dd9229e0415b61e5d098caVirustotal results 0.00% 
2023-06-15UIApMzGOT6Xo.jsjs 4fec865550ff53e1647b8c412babf52ed957463d46ce0c321090e55abf8891b1Virustotal results 15.52% Quakbot
2023-06-14T2KagIr2h3FODb.jsjs 7c3c68cbfe396127160a25bcf3af6eb800dc5e9a191cb02e6be2c98f1a472e57Virustotal results 0.00% Quakbot
2023-06-14zuLtOdwwK0id.jsjs ba1f849658b80a35311eba3278b4c136bb35cfa017a1f1cc64ed840c0b901fffn/a Quakbot
2023-06-14EzLOp9wfUlDg.jsjs 08b534781c91fa59da7feac81cd6e9fea528fdcc84bb91f19705a9e00ded819bVirustotal results 17.24% Quakbot
2023-06-14kQSkj5jcc83xWU.jsjs 964c22440234b645517e6252c5c09c6b4577df7416335aaf23f14eaf29f6d859Virustotal results 15.25% Quakbot
2023-06-14636pcrsozGvh.jsjs 2ddef774dc4bfb6516396d8de580f0960d0f225e79077dbab7d317ad7b67eadaVirustotal results 0.00% Quakbot
2023-06-14Jr7BHbvqh10W.jsjs a373fd606aa390905c9942f09f50a6c7bc916aeb87426e82c291cabd34f6383dVirustotal results 0.00% Quakbot
2023-06-14Dkk3QRf9jrwO.jsjs 835970e7580f24389b039182319c8815e69374f65a0e3740478682955dfb44afVirustotal results 0.00% 
2023-06-14rNtvBobPaZqWwU.jsjs eea96900b352686f4027368ea486dc36e9a045408a1d0648815c483533f7c7f2Virustotal results 15.25% 
2023-06-14JFJuVrH8uMmV.jsjs 5e92672bf7df5ffa648fe80afc84767228698c68568d57820a3e6bf224b89ce9n/a 
2023-06-14freys90fXXS5f.jsjs 466dea06686c065a5ac52c98c45beb0fcfde21d035d466604b37245d7746432eVirustotal results 0.00%Quakbot
2023-06-14fD5Au6bGTvVCE.jsjs 0787387747384f631c0a746905175f19f71d462cfb3cf432d69cf92ff90953e3Virustotal results 0.00%Quakbot
2023-06-14Ny2FasaLCKN3d.jsjs e24dae59a010130abde32f4eaff31e39090feeea4c7c45ae39cf343fccb72881n/aQuakbot
2023-06-14v7lIqZybcPuoea.jsjs e8f30ac72b6c6453394052ceed837005baab5a05ce4faafcd090b104cc7c2059n/a Quakbot
2023-06-14YabCFLVs3Wbx2.jsjs 7e61735403cf258fafd12ae3d3ff59a4263a605025533a7cb1a6715d82dc165bVirustotal results 15.25% 
2023-06-13IDzOKgUMidTj.jsjs 2e6c65708101978493d33039a24987a1b46b65b3c1795df913b4564efad64b7eVirustotal results 0.00% Quakbot
2023-06-13ds3U0T5ga7kXT1.jsjs 76230f54edbcd2f29188eeb0993b0cfc09222f17387e75e135166a556439f73aVirustotal results 0.00% Quakbot
2023-06-13plN8vhzXlLAw.jsjs 57ced807ed0b808f86d5038dfce4c393fda85af6b8ddd5b952608bff0cb90973Virustotal results 15.25% Quakbot
2023-06-13YWZvorgC9Vw4H.jsjs 8a9f624cffd86aa962676fc64c27678aeca0fad692090a9c3ff88ef85ca254b5Virustotal results 0.00%Quakbot
2023-06-13FmdlfRNledGNT5.jsjs 7f6436c40c2b2d104add09034d693f6871edd26b6798e272e5e4a3894ef5bc65n/a Quakbot
2023-06-13L3vvZVezBdHU4i.jsjs c9d6771d7ec3061b33877b09e73db0925b2a6e360b41b2a2b1c8eb001e28a06fn/a Quakbot