URLhaus Database

You are currently viewing the URLhaus database entry for https://letstart.us/suqa/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2661029
URL: https://letstart.us/suqa/?1
URL Status:Offline
Host: letstart.us
Date added:2023-06-14 16:56:45 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-15 02:14:05 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:13 hours, 55 minutes Good (down since 2023-06-15 16:10:00 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BC045_Jun_15.zipzip d54a89021fd4610f66270bb1d0b3b38ae2eddc15e3a8ecb3f405e9a2e8dc9e23n/a Quakbot
2023-06-15document_AB762_Jun_15.zipzip a21ffccaa3b543aad629370b57fb2f7a5583d453a700bdb9b3e1beb0605b72dan/a Quakbot
2023-06-15document_BD732_Jun_15.zipzip 3c02df1fc6d6b685fd5455153db7569ffd7a66acee399bf6696d36a4bab7b5fcn/a Quakbot
2023-06-152ZqMdXM7fnQpv.jsjs 722f71b7ae233dc32ad9bb780aae59e19fdb1b8f230170dfc655f999ca2d97aaVirustotal results 18.64% 
2023-06-15OJhaaavp3jCZ.jsjs c1de2d0054eefad63e0ac20dec43bfa2e3b7e04b5ce2c80a231c1f68ddded1b5n/a Quakbot
2023-06-15aFh2Zwyr6LDG.jsjs c95d61b39b0bdde6f15359dfaae326fa9b13e29f8976d8b00d117287d590565cVirustotal results 0.00% Quakbot
2023-06-15zYTIk4Cuv4EIG.jsjs 16b36931b6ba6251bdb5ad4e7c13e2f985f640b4f70e071170b063acce143247Virustotal results 18.64% Quakbot