URLhaus Database

You are currently viewing the URLhaus database entry for https://topan77cool.lol/lee/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659401
URL: https://topan77cool.lol/lee/
URL Status:Offline
Host: topan77cool.lol
Date added:2023-06-13 17:52:30 UTC
Last online:2023-06-15 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:54:23 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 23 hours, 10 minutes Poor (down since 2023-06-15 17:04:27 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_DB437_Jun_15.zipzip 95a0845fa4f12c5f3965e0d8f40d4f22368a646ae4f5d11c4bcfaa509d3894e2Virustotal results 6.67% 
2023-06-15document_FD539_Jun_15.zipzip a2dca8693a9bf2aec4d6f0e2a6e9b672bdf2c5db3550b2f3005f267aa909319en/a Quakbot
2023-06-15VKxZpRgcY83vSp.jsjs 9bfcfbe8e93d0827308d1dc96446ec64cd7a27a4a6587ecacf056e42b7f0bfccn/a Quakbot
2023-06-15roJ7emU40D0q.jsjs ffa83ada85aa0df0667b1e03f52a99245b3216e5976125c1edec63986452619bVirustotal results 15.25% Quakbot
2023-06-150Tc3FqsHB4ep8H.jsjs 6d765e2a4dfb5323d56bd3c9f1b843f7a03a6d5b408dcfd20b4f1e5f28e25967n/a Quakbot
2023-06-145KpWR7zMfIbL9l.jsjs 8bf9b1ba01c9ac542b665cab5fcf1a2118007d348c93728794bcb20c0ba533cbVirustotal results 0.00% Quakbot
2023-06-14MkRgOI9rr2J0dB.jsjs 8531318e0e87fb75bd117adf1088cade8597e9b6c5f99a15e8d0f7b93179a747n/a Quakbot
2023-06-14docu_EF925_Jun_14.zipzip 10e566dcc281e6b991c1793ec7bb7fcf5340ff7c607fbc94780502a1567b8bc0n/a Quakbot
2023-06-14cz3EfRwcgvveH.jsjs 5d8b5d90a7cf253503f2a8169b135b71efce84e4c2cbf5feb7746dd375ef1720Virustotal results 1.75% Quakbot
2023-06-14ybJEMrPul36U.jsjs 6d27d8b0fe876b58829c60297dbe4ea1b17db19bfcd8e8dccfb53521350e1a48n/a Quakbot
2023-06-14jOVr7ffOa2Cw.jsjs c22dc4173284f84493d9f11142a4f3e459c34fd1a413ca34a8c22e01b926463eVirustotal results 0.00%
2023-06-148gWHA75aF5WS1.jsjs 24817dece5d1c1d26782959695a0e801e003aca0cde39d87ccd547a3d2041a9bn/a Quakbot
2023-06-14ZZrvn6j1TCC6c.jsjs 5a652761cdc46fb64dfac6c2d3d9ab2bd6108ccef5860b411746c8de1c6ccf59Virustotal results 0.00%
2023-06-14Qpc6kNoMf3FZO.jsjs b47346d6ccad24ac4dfd9109016c3c3c9035effb8092e3f7fae79935768f436fVirustotal results 18.52%Quakbot
2023-06-14esjzcrxWKBqy.jsjs 96984f4d92e891aed7f951855292c8b034afe2e6683651f85f401cbe8246d889Virustotal results 1.69%Quakbot
2023-06-14GV1wJwTtmyr9.jsjs eff9d6ca2a7a7c9dcee86083137fdfe4fdf760faf1e81355857e68939607b1b0Virustotal results 0.00% 
2023-06-14YiCTSF7vTKxcH.jsjs 17e0b63a9658844a7abe937e437ad78b32a0b831718cf4a8504c81f558243073Virustotal results 0.00%Quakbot
2023-06-14uxRIFAgje21o.jsjs 8670dee51f9e9588f77e0da71d324085bd9f779001244b568f807e6e24782340Virustotal results 15.25% Quakbot
2023-06-14LBwdkF3na7Y2.jsjs 978259ac07ee66dcc817ab3d39ba82672a31ad51ebdfcf56024bba26859dbaeen/a Quakbot
2023-06-13RDaVUOTJvy9B.jsjs ceea44b69d9990b83357e10cc5b3024dd746579c1a9b43c63b514b713532f6e7n/a Quakbot
2023-06-13gVOXlpElSl5s.jsjs c74197b3621923b8654b61bec5ce475ecb8ceeb92361f4d2f440c97a0a8dc5a4n/aQuakbot
2023-06-134udLr9ip6m6xDZ.jsjs d3e88d1a1e4e2c37ab2dc5240ef71341c67db394e4ef273075456cb439fa786dVirustotal results 15.25% Quakbot
2023-06-13eozfQ66pGEjjz.jsjs 0e00ded5f9ad6662d955770f086ae1ed52d0eaac9375c87f9ca0e2d2ed2145cbVirustotal results 0.00%Quakbot
2023-06-13J3kta9ixUPd9g.jsjs 6f0ec879319b236a6b0a8d14638db2ed810c37f18f4aec29f409112726f6b740n/a Quakbot