URLhaus Database

You are currently viewing the URLhaus database entry for http://truongnoivu-phqn.edu.vn/media/bollivo2.1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2569402
URL: http://truongnoivu-phqn.edu.vn/media/bollivo2.1.exe
URL Status:Offline
Host: truongnoivu-phqn.edu.vn
Date added:2023-03-14 04:27:12 UTC
Last online:2023-04-13 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-03-14 04:28:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 0 days, 2 hours, 21 minutes Bad (down since 2023-04-13 06:49:28 UTC)
Tags:32 exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-04-06n/aexe 0970ad78ddc60372da2845004d617778e9b5ef724be801fed484bf032db06a08n/a 
2023-03-16n/aexe 9a99b7f9cce8d58631dc7fc88e8d3bea94afc5b29a7d64c968223fbeaa09a73bn/a 
2023-03-15n/aexe 08f54668a9775d9e6bea34c971c39b5ccf92fba203acf9b2bdbe7c19782b9ccfn/a 
2023-03-14n/aexe d952dfcbbb2c05f767753f8430277a036222227b92858a8e09695eedb2a8ef96n/a 
2023-03-14n/aexe 91541f68b8b5902f7adcf39aabf726e4f9204b1b16d6d372081be04042588390n/a 
2023-03-14n/aexe 8e30dcaa26bc44a835bda83ff3374cd0aaa2f2a857414cb6b2099ac2c5c2cf27n/a