URLhaus Database

You are currently viewing the URLhaus database entry for http://man.myanmarfas.com/ds/2112.gif which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:938496
URL: http://man.myanmarfas.com/ds/2112.gif
URL Status:Offline
Host: man.myanmarfas.com
Date added:2020-12-22 14:55:23 UTC
Last online:2020-12-23 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: lazyactivist192
Abuse complaint sent (?): Yes (2020-12-22 14:56:02 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:14 hours, 13 minutes Good (down since 2020-12-23 05:09:44 UTC)
Tags:dll Qakbot link qbot link Quakbot link SilentBuilder tr02

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-22n/aexe fc7a4edf9d9984d4a53b4296f0d0160436144bc5631b8c5b445a86f3bfa9ff61Virustotal results 57.14%Quakbot
2020-12-22n/adll 1e617483ef0b3de4ea1e74494200c9503947ea5a31c05eb01e14454fb78edaa2Virustotal results 21.74% Quakbot
2020-12-22n/adll bcbd804aff1a584011f23f6f95d3dc5e59c4f2341236ec6967fa3c29699d09e6Virustotal results 35.82%Quakbot