URLhaus Database

You are currently viewing the URLhaus database entry for https://ramdungexpedition.com/aisl/squfgotaiu which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2321215
URL: https://ramdungexpedition.com/aisl/squfgotaiu
URL Status:Offline
Host: ramdungexpedition.com
Date added:2022-09-28 18:11:40 UTC
Last online:2022-11-21 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-29 00:47:11 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 month, 23 days, 0 hours, 25 minutes Bad (down since 2022-11-21 01:12:22 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-25QIJMGjR.zipunknown 9159962572f95b9bac12bc9bdb7bbca4a5fc2ccc0ba8ee8656c856a91344e9c7n/a 
2022-10-15WcPwJhg.zipunknown f1be434bf5074bb49d0fceff8d07e46eca82121b111658a6449a7f1d758b69c4n/a 
2022-10-11O_3979692212.zipzip c1bb4e8285c0ebabc28598fb9c8d8d2af18b406a5629a093f6261e27656485bcn/a 
2022-10-09Co4126437676.zipzip 45d523a5f9f5e0f3f5f103fba3bae94043a34f6b09b4c5b2cc75ed84cca6e8f0Virustotal results 36.36% Quakbot
2022-10-04eEdbtp.zipunknown e80cdcb2ce866445a58606a20e5959fda380740a515b3c94886b5652682f2571n/a 
2022-09-30Card1769998150.zipzip ccc57a65c54bc21fa2967aabc3265fa6c26f75eeb911e59437ff87a23df07fbbVirustotal results 1.59% 
2022-09-30G2467890268.zipzip b4f9f1b9b56dc3db9aef539ecbb335be142e163e414d578afe0ce05c13fd1ef9Virustotal results 3.17% 
2022-09-29Gall1753516638.zipzip 34d20cccd0b3fb8021adf69300fd213f6952f01ddb977aa7371beb975270c731Virustotal results 3.17% 
2022-09-29Gall1000530258.zipzip 254f3b1680b1c6ec05cc30cf0ce29f95b79c484e64e3b1499640fbc423ba0348n/a