URLhaus Database

You are currently viewing the URLhaus database entry for https://rajtravels.co.in/tc/isalmotaeiteroen which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2321319
URL: https://rajtravels.co.in/tc/isalmotaeiteroen
URL Status:Offline
Host: rajtravels.co.in
Date added:2022-09-28 18:11:57 UTC
Last online:2022-10-05 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-09-28 18:12:13 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:6 days, 13 hours, 15 minutes Bad (down since 2022-10-05 07:27:30 UTC)
Tags:bb H322 H436 Qakbot link qbot link Quakbot link TR U425 zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-01C656727392.zipzip 51d3e92409e9441545050bec7b16df97969235a6f32ba080470bffbf303b7dd8Virustotal results 3.17% 
2022-09-30P238467391.zipzip cc897aa5188bb3b7ca92ed8801194ab8759a47cd04157369b75c9e02a5a30ca7n/a 
2022-09-29Gall707758465.zipzip eecd5f4813e2ee622aeb849a645ca1fffd1069750707ffe9112e0a8ea7078ac5Virustotal results 3.17% 
2022-09-28ZWCJPVFSGF.zipunknown 8f51fb030fccd3f89d18c8e0778b56cc535cee7d6c4be31f7dce8fc697d13d0fn/a 
2022-09-28nsbJBjd.zipunknown 609c59ba964d02dee3f28f16ca8bd873b45c07bcdd7a59ad0468e02fdde2c686n/a