URLhaus Database

You are currently viewing the URLhaus database entry for https://letstart.us/dtf/? which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2661829
URL: https://letstart.us/dtf/?
URL Status:Offline
Host: letstart.us
Date added:2023-06-15 11:03:38 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-15 11:05:55 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:5 hours, 22 minutes Good (down since 2023-06-15 16:28:10 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AF759_Jun_15.zipzip 9df66a0aaab76bdbb5d13c4646d7a09ab96994857259f5caf5dae315dd3f336dVirustotal results 6.45% Quakbot
2023-06-15document_AD034_Jun_15.zipzip 038f4f6edb3a1fe3213835c61cb47da6ebc8f7bd4b4ec45b404177abf5c308ean/a Quakbot
2023-06-15DlSfHBx9tUpMl.jsjs 07ce4305da692406f27a31e85d2ea9b4a92824e0b46c612943aac2e71a77677dn/a Quakbot
2023-06-15QXPxYvijJlTAkf.jsjs 2d5e213ca31273eccf47a9deaa6d02438903363ea6ac9b36db2a4b8ff6bc1669Virustotal results 16.95% Quakbot