URLhaus Database

You are currently viewing the URLhaus database entry for https://ivgreen.com/id/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634284
URL: https://ivgreen.com/id/?1
URL Status:Offline
Host: ivgreen.com
Date added:2023-05-16 13:42:32 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:45:49 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 9 hours, 0 minutes Poor (down since 2023-05-18 22:46:04 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Miqlowfy.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Zvtul.jsjs bbcdb87a842c5157acea98f0cedd358f764e2613b6a635e4f9f5946de8c07780Virustotal results 13.56% 
2023-05-18Bkfd.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Bjfzn.jsjs e3fcf880ac439125aec44d2e5ff0c5ec8be06c1291589710ea72bbdcaa4f5c08n/a 
2023-05-18Xokxjz.jsjs 0a6a1598b501c10c9f5b674586502de9eb32d51063c42dfce137a78f56aa4388n/a Quakbot
2023-05-18Uypcgsy.jsjs 67878c5898e4d6118aea2d8059896ec493c2cb1b7f3bdc563068504a0bca9373n/a Quakbot
2023-05-18Vkty.jsjs 828ab9b198ace6540bab66d12bff28bf5b11bb1258df06ae467240d2ff175f1bVirustotal results 24.56% 
2023-05-18Wzdt.jsjs f252bb947741e263a585e14d04e2ccd38b535351fa818233c9ab294b4b174275Virustotal results 27.59% Quakbot
2023-05-18Wxqqt.jsjs 57924347ed17b5b79fa35f9c3f130733079566dd527de61c8d1691c0e4f0a7f2Virustotal results 27.12% Quakbot
2023-05-18Ozan.jsjs 8fe6b80c39f345411e663560d164edb44cbf0ad7ba4914ba79f02bb403348f27n/a Quakbot
2023-05-18Ovxo.jsjs 9f58336c0b0f6cde0a91dbee871cad45a315c5413863ef2b29affc9c949ee72dVirustotal results 32.20% Quakbot
2023-05-18Kzqiw.jsjs 749721b74088db119de7bccbe5cea0c9486f42bb570461ff262c5ed324b4ca16n/a 
2023-05-18Efgfzy.jsjs f5aa3695ae64a4d74e1b05d3df7788674c2071ec3266a262521991149f02fc95Virustotal results 16.95% Quakbot
2023-05-17Imfu.jsjs b11fc0e56235f908dd870eceed98215c815c131e83913eff33f70f528e369dd4Virustotal results 30.36% Quakbot
2023-05-17Vebmnf.jsjs 0b26bdb33f82264e6ee139e028f16f756cf3c276a5c8fdc923aa5d5e2e385872Virustotal results 24.14% Quakbot
2023-05-17Zuqv.jsjs 2ffe30857db286ab5839fb47499480fff446371b3c1f8df2d8dde6853266f088n/a Quakbot
2023-05-17Lsvuaj.jsjs b76a46e9b0db483e342c390f25663222fee2e67cb7670205636c7ee748850b86n/a Quakbot
2023-05-17Mdqse.jsjs 50181b4f3b73fded444a5822e9aae57537b05f693c1a1887d0f8b54f0f597de3Virustotal results 24.14% Quakbot
2023-05-17Kiuwcu.jsjs f91b22ef75c62115177abfa54ffc898319098f3de31ddf0b2a964dae96c3b376n/a Quakbot
2023-05-17Cmmbjv.jsjs 9fc93269f064d50db15333e3dbcf15dccb35094dc51bedfc465ba99ce6a37953n/a Quakbot
2023-05-17Drpumycl.jsjs df3c1cb9068b8bb463df72a5a54f4b4a6da6d820e8910c0101d49c35134f17b7n/a Quakbot
2023-05-17Ofiow.jsjs 225e6f5fc60a2b36a0b40475781eae7f83e9211f192e0212c67536cf89ddbbecn/a Quakbot
2023-05-17Ttliui.jsjs 08efe1240a1020f6614aeef026e44e61095a168822a995c482ddceda653f4cc5n/a Quakbot
2023-05-17Efct.jsjs 66e11241df94efae0fda8fbc1877aab2a002ff393e37bf5559e1d06d509e434cn/a 
2023-05-17Wrafr.jsjs 4f700f3d8bf9dab1345f916b2bb1f5dfaf433cb22ef98b1b8cfe9ed7af9ebc65n/a Quakbot
2023-05-17Jhfqwf.jsjs 29bd094138bcbe3dc648cd3669b8a9743f8f45b397cfba4a3709ee3b3cd888f6n/a Quakbot
2023-05-17Fugixy.jsjs 1db45edb21388012e0753d195caf6652e67d396df2201cffb6a997f03bab3d9fn/a Quakbot
2023-05-16Hgwbmlgj.jsjs 13316964309ff9b49e266ccc4fefa190849fb442a66852cb7ac4d3b2ff692f3an/a Quakbot
2023-05-16Afjfcfsi.jsjs 9b4b0ba4ecae33a92d8a1e2aeee7eec3619f73a3481f14f43b86d9ea3f75be77n/a Quakbot
2023-05-16Tkfw.jsjs 92ffa9f1c5747f29f53dd7d520309872f9386e278a37436ce130f7ddfdc1c3a2n/a 
2023-05-16Vccwlqu.jsjs cafd5a18d3ce75d3b5f04d84c3522b7798081fc49a880f1f8df0ac79bbc5fa21n/a Quakbot
2023-05-16Tfdnwy.jsjs c2a9eaad930db686d04dac7ca0bacd6078bf87aef7a6c6051488972f62bc2dban/a Quakbot
2023-05-16Exiqehps.jsjs 819849ef05918e0f0c22d93528f2a8bdbb42243b0417d1dc2c4e5b7b3d7626afn/a Quakbot
2023-05-16Bvvx.jsjs 27d13113e11ff456134793b467103c106817d17ad9f9633324c3a21ec217abb5n/a Quakbot