URLhaus Database

You are currently viewing the URLhaus database entry for https://lifestyle.mn/nre/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660039
URL: https://lifestyle.mn/nre/
URL Status:Offline
Host: lifestyle.mn
Date added:2023-06-14 09:02:22 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:04:36 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 7 hours, 22 minutes Poor (down since 2023-06-15 16:27:18 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_CF901_Jun_15.zipzip b983426952e8271724db7c02621830a89d919578015243c8aced8586c47eee3fVirustotal results 6.45% Quakbot
2023-06-15document_BC430_Jun_15.zipzip 881aad0e92f980125586cf41f05f97fe98cba7bd3934dfe1b16bba7107a49cc6n/a Quakbot
2023-06-15document_AD031_Jun_15.zipzip 47f31071b9b836d7a72dd51acd1d93f1630c039bed34f20fb1dc244b0e4dfd97n/a Quakbot
2023-06-15bkzBbDj7vsCy.jsjs aefbd8c2f0696e960a202d2255dc852c710020f4296ac1997465e208027f6bcen/a Quakbot
2023-06-151CCayaWPLtopto.jsjs e62aab4e64b901e5725f3db310edf7fe45de476652f5bbf979ced6b88a919936Virustotal results 0.00% Quakbot
2023-06-15sHrBoM1L7pRd.jsjs 6f075611ed0e6cc57b7e8789bd17486b2a52fd561a83a4c9589b01c2f5953dddVirustotal results 15.52% 
2023-06-15BRrKvdFlYuAM.jsjs c18d345c3bc268f9c89f4433de494633707ce8de6854d71ab91b93e234ce6209Virustotal results 0.00% Quakbot
2023-06-14cOhhcWB7DZM7Vu.jsjs 4a2eea1803cda3dd4f98b8bc5004057ed6797b13021a03f15eedb9f8183ff3e9n/a Quakbot
2023-06-14Rm2CHCYN9QMGU.jsjs 4d610364e865325ba1a869c0f6514e7d2bdcaf5c4a5d60d0af65789aa0bb692eVirustotal results 0.00% Quakbot
2023-06-14docu_EB281_Jun_14.zipzip 71ece756d0a82c68c002571bc8010e13018ec7860d24aa6d9bb595698e10d9c2n/a Quakbot
2023-06-14docu_DF631_Jun_14.zipzip dfe99e49909839abaa99142b09b1e8eaf4d5ceb9e5880e75b045fc2c805c4f7en/aQuakbot
2023-06-14lZlIGLEkWMLJdO.jsjs 2c9753f3b2faf3e22fd3b6ef3be9c9edd4c22fbca372a9946b1fce7d7518c72bVirustotal results 0.00%Quakbot
2023-06-14RLXtT4Jj59nEKz.jsjs 2ba3c60a38843bb6e94665abf69b0b4aacd50fcc34a699882d1c692a97f0c53eVirustotal results 15.25%Quakbot