URLhaus Database

You are currently viewing the URLhaus database entry for https://bamhealthcareventures.com/reni/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2633704
URL: https://bamhealthcareventures.com/reni/?1
URL Status:Offline
Host: bamhealthcareventures.com
Date added:2023-05-16 11:25:58 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 11:28:44 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 11 hours, 21 minutes Poor (down since 2023-05-18 22:50:29 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Uyadbm.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Hlzrkv.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.56%
2023-05-18Rqcuhdk.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Cjbq.jsjs 6974f5fb489ff2db797c474b0a452c5cfd1593ff3c9fe5e44f9b264891f76e68n/a 
2023-05-18Vkizobq.jsjs 1023d2a3febc48f033a53509d7c13ab44b981e38169392d13c7ad15e12b37515n/a Quakbot
2023-05-18Naifmuf.jsjs 3ac894a6a388d20bc81ae5f8474ee788079f5036842b1542150a55c8fed2059en/a 
2023-05-18Psgbxgzh.jsjs 43b5fd987f46196b07b603e95e51b7c7676ad0784f913f1b136dcf29bb46e808n/a Quakbot
2023-05-18Ycvtvl.jsjs c63bbe3dc673315fe3da91f26e53709a754546f9d2fe9fdbbd7dfebbf28c116fVirustotal results 23.73% Quakbot
2023-05-18Qlapvkci.jsjs 2971e245d875fcb96bbbbcff59e1a34e0490ae85f5e8abd688b28772bca0b30fVirustotal results 34.48% Quakbot
2023-05-18Qyokr.jsjs 6a2662394ca0402750ab97d8fe3a3010858b9dd07c373ce3b2579f8f0b13364eVirustotal results 27.59% Quakbot
2023-05-18Mqpf.jsjs 611f39b0fe3d00c6bc886929f93aab5028192d0d7398bd8621b700c05e99dcc9Virustotal results 25.86% 
2023-05-18Lfmsgywz.jsjs e7958ccd8a002219ae5c0a15fe85c42f33e3433270f0ba102d597f19a494e2e8Virustotal results 27.12% 
2023-05-17Fxffqlnk.jsjs 42d74e9be0d442e0bbebc6134157922913abc72510b235bfa67b53092757a2f4Virustotal results 30.51% Quakbot
2023-05-17Xylumcrx.jsjs 403516fd88c6e48a70d5ab2c1e966024e8e46c5403dcaa8dbb3b56774715cf30Virustotal results 25.86% Quakbot
2023-05-17Vnza.jsjs 8506e3c5de62fa6173656a51f4f41a0986ccb9fa55bea9cfcb878c6df2bd88c7n/a Quakbot
2023-05-17Rqrizu.jsjs b3c3f0880fe1ebd5b9f5146a8164da0834ee29a37e5a1cd8e534efe15c786daen/a Quakbot
2023-05-17Xguztkl.jsjs 73abfbef5c169e5239c78d4c04f3d18f7f72490c2ca0cbbb33d92cac9675dd16Virustotal results 27.12%Quakbot
2023-05-17Inwvcjy.jsjs 9c3ce9878a22fffcee6c677d536eef828546dc7592693cd8be968e6235ceb49fn/a Quakbot
2023-05-17Ageq.jsjs fab89deda2e8de1afcdf4d43b713652dab42ebcad6b4eddcd3b225188a7e3078n/a Quakbot
2023-05-17Meakwvcf.jsjs d605ef2cce3baf9a1147b611161b5d8403501379e2aa824c4c9ee2601b4a6a45n/a Quakbot
2023-05-17Ntlbkwk.jsjs 53cec6623e4fc394a316bd6b9ed923696a54ff7d863b8d14a8f8e0d31d49b4e4n/a Quakbot
2023-05-17Udutggm.jsjs 9e5e0be99094f25c2ea7267b35a38451f6a27abb4f9ff0d7b2bac868a09b9253n/a Quakbot
2023-05-17Hyrmc.jsjs d521d1c2bc22f1173cdeee645da0e6b36170a3f8de3d5aeb4faf4d5eccf75877n/a Quakbot
2023-05-17Svvye.jsjs 7dde39fc6ff6417547b4da4b13ddc4e4012845d5d35361072c7bdacb9ef06248n/a Quakbot
2023-05-17Oagr.jsjs f96a1262a17779926a2e585dd0c7636a13ece34ca7a3088cfa1241d4bb9ad47bn/a Quakbot
2023-05-17Qxhirklc.jsjs e07853a7f69d7f6d57b2c19a350771a4b65b124f403027814860b5715c5691c3n/a Quakbot
2023-05-17Kzjbni.jsjs bc5f1a47c01c60db586e596187b62d547d0e96c55c2a972f29262a5a87f0e6c3n/a Quakbot
2023-05-16Mtzab.jsjs 6322c97cd509ee8f3655541fbb99ac5afceb1d20a5de3141b063a9ccd69e7351n/a Quakbot
2023-05-16Uydfzvr.jsjs d77929d5b5b94c4a785297b8a6be7a92289d464f239b053b588e8acd116e2599n/a Quakbot
2023-05-16Rpqsvd.jsjs 27a63725c5e82b8919d4822b9b8256d5387e70af0aafd753ca532c34298c37e7n/a 
2023-05-16Vlsvsw.jsjs 9b5eb0e0458d2a43c4e9efe7618accabc64a919b5dacd39f12948b28c5c34f7bn/a Quakbot
2023-05-16Mtlypi.jsjs 88f7cd090c9523aae633dcf78b519d2320f807a8f9a1ffdd86c9507bcd1882fdn/a Quakbot
2023-05-16Yqdk.jsjs f1ceb9d80389ca712b1cb5807ac21189e1ec264f5c22238881be30b8c40e1105n/a Quakbot
2023-05-16Dqip.jsjs 455fd505305c463b61ad8ea0f20243675fd8f7f055586ff38495032a1c9308een/a Quakbot