URLhaus Database

You are currently viewing the URLhaus database entry for https://foundersdoc.com/idie/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2635661
URL: https://foundersdoc.com/idie/?1
URL Status:Offline
Host: foundersdoc.com
Date added:2023-05-17 13:06:15 UTC
Last online:2023-05-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-17 13:08:58 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 8 hours, 17 minutes Poor (down since 2023-05-19 21:26:45 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-19Tjehcng.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-19Svtjed.jsjs d7522ab4f64ae0950e24bb00df9157136bbcb900ace0c77bd1a46f06149bf37aVirustotal results 23.73% 
2023-05-19Orup.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 25.42% 
2023-05-19Octu.jsjs 51ffefa8a10b6da720a80cec4735fe173669e7c974946e46c8dda908e824d8a4Virustotal results 22.03%
2023-05-18Oasrwyua.jsjs 76443e093ed6d6e3961cb5f9bbd546bab2d05f6bc2536c5744dc86f7a769bea8Virustotal results 30.51% 
2023-05-18Vcock.jsjs d76b1300fd995ec8def343df0450c11a58a217803fee3749db4afacebc64182eVirustotal results 22.03% 
2023-05-18Zluquls.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Kwenac.jsjs d3c6e06204212c1aeeef29809460056535cba3beca8cf163b7c8719671ef0c9fVirustotal results 22.03% 
2023-05-18Hdrc.jsjs ca742655723aed0ca42b7dcd811476f1d162c0610c79c43b974e9f2c845de564n/a 
2023-05-18Xobpuju.jsjs 16e669d4d5391d00940846a4f52891c84d175cd3dabd4f776ef0b2b352c4f2c2n/a Quakbot
2023-05-18Nhnyn.jsjs 783e0a457afb1237e0956e6ff847bfcdb49ee23036f51b4621b534f54d67112cn/a Quakbot
2023-05-18Vnsipu.jsjs 77c78781fbf40291d31c545dd06a094505a49bd415cbeed6b922cafc6af07586Virustotal results 28.81% Quakbot
2023-05-18Nnmnvu.jsjs e84b4920d25503f9505dfe8813b964551aa485cc176eb30dc5ac5e46dd5d56bbn/a Quakbot
2023-05-18Xjgcihvq.jsjs ec6f55b9c56d3dead8b8490dfbbcccadcdfef62b7d67c671b8d0ee9620f4b74fVirustotal results 16.95% 
2023-05-18Iskdrd.jsjs 8110c40ddb65d964d81ab30f4c4f9bdce11b8956b986d647f4b81c4c0652f5a3Virustotal results 31.58% Quakbot
2023-05-18Vlli.jsjs dc776fb044bb27e20a16f383ecdaa44a67be283f4902ddd48f1f6cffd24d036cn/a Quakbot
2023-05-18Btpo.jsjs da144ecfed0906bbac01d116a74626cd6fd7ec833680cd9ff8107dc94db16496Virustotal results 16.67% Quakbot
2023-05-18Ywhvcytp.jsjs 3f883b067422272c3b10eea88505351741b599d103f66676cb75912106735cfdn/a 
2023-05-17Ikqa.jsjs 34af4640c3591095a1562606faa096b2cab669c17859f8b99df4321999b17373Virustotal results 22.41% Quakbot
2023-05-17Jjlibt.jsjs c5a390d1bf67c2241e5a9cb33cab3e83b41d4319c494c9f15d864cff3015e95dVirustotal results 15.52% Quakbot
2023-05-17Nldyblw.jsjs cca9ae0f45d9d362a7e18d9f86ed7a18a1340c3f3d4811c7a2ddc658408bd496n/a 
2023-05-17Tycy.jsjs 266bfb248bbfb5fafc879d0a26c731499ccb3de4c57b64ce4b3a3fc6f836b93bVirustotal results 25.42% Quakbot
2023-05-17Hcna.jsjs 50ebb94dd22b6d976b5ec46e2aaa6756dd807058f1a4fe1497d72c4a355b3c2dVirustotal results 25.42% 
2023-05-17Enuancgz.jsjs 655729ffaa1d79b40a1df6017495f362432d5497a1c79b18220fdcc46d21f2aen/a