URLhaus Database

You are currently viewing the URLhaus database entry for https://rbanglam.org/pisi/otblipsloeumir which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2321249
URL: https://rbanglam.org/pisi/otblipsloeumir
URL Status:Offline
Host: rbanglam.org
Date added:2022-09-28 18:11:49 UTC
Last online:2022-09-30 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-29 02:28:06 UTC to abuse{at}contabo[dot]de)
Takedown time:1 day, 18 hours, 51 minutes Poor (down since 2022-09-30 21:19:58 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-30Post3371830049.zipzip 05eb892ab95f5858f9b995c74b5a6162cc3a886e254c020af169c16102748df7n/a 
2022-09-30Gall895448366.zipzip 5fc427bf226a4841bdf7d3ddd692c18671ac7e249017a048b9da8ec40ab67189Virustotal results 1.59% 
2022-09-29Gall1206227132.zipzip 76c68111ac533b0de5e22e84e2197dd62b2df93747c526830687eff56e696263Virustotal results 3.33% 
2022-09-29Gall1411380347.zipzip 1ae242874d198c3b3d79f834bcb4ae2532037ae6bc2af549df70f434fafeb502n/a