URLhaus Database

You are currently viewing the URLhaus database entry for https://ruouvanghanoi.vn/hn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659432
URL: https://ruouvanghanoi.vn/hn/
URL Status:Offline
Host: ruouvanghanoi.vn
Date added:2023-06-13 17:52:41 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:54:53 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 22 hours, 21 minutes Poor (down since 2023-06-15 16:16:40 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_DE285_Jun_15.zipzip 5972020d8163d6e5b0cbffc83924f4444b9c67cbeb59229bbf04b48dcd3ca2ban/a Quakbot
2023-06-15document_CE029_Jun_15.zipzip 00349ef5de79fe9711928f792d6aa8645575bc0ceeffd197c162d3a6e88f5b7fn/a Quakbot
2023-06-15RrF7sJesF0Nu.jsjs cf3e4745a3cd0688c2708db5eb23485212fbf6f47f7222814724fb36520bcf76n/a Quakbot
2023-06-15JlqQfhNMAju2.jsjs f3c599b6bad4e2de8eb35f217ae9cc4ad366d3aebb1b7d6922883407e3320172n/a Quakbot
2023-06-15ipyN0QdQlkfqB.jsjs 0e7a164b57ee62e63910af05f48e1fd4c727212c4fb0784694e2da0776832d79n/a Quakbot
2023-06-15ZbmzK2P8STIzF.jsjs e67844aa21e6669024383834a390eb68ed63fcd064672c00b13d5a686b63da7aVirustotal results 0.00% Quakbot
2023-06-15ctzeZUQb74pE30.jsjs dff47bc07686c0167b7d220b6ec31223869d061d77669567275680460b602ed4Virustotal results 0.00% Quakbot
2023-06-14DWk5ua5ulkSZg.jsjs c8bb62eb4bb6e62bfacdb832780804900abc32cdcd2e0e45b1992a7905727926Virustotal results 0.00% Quakbot
2023-06-14docu_EF507_Jun_14.zipzip 84409de54122143989dc0176dd30cd263dc5b13fcd1c279c2545119515a9e20cn/a 
2023-06-14docu_AC864_Jun_14.zipzip 4fce02a36b80b19b72fa8938d520946add81f74713a79183cfc28482c705bfb9n/a Quakbot
2023-06-14buwxkh6tcFh7iq.jsjs 1921a9b34e0f70f6cd73ef0a99e7dc401f82e4505e70dd373dadcb3252beb81eVirustotal results 0.00%Quakbot
2023-06-14esjzcrxWKBqy.jsjs 96984f4d92e891aed7f951855292c8b034afe2e6683651f85f401cbe8246d889Virustotal results 1.69%Quakbot
2023-06-14Qvp9KA6vRsxre.jsjs bb8759ef43fe68f47088825593a27fefe39693d115e9935c8d7c14201e0ac965Virustotal results 0.00%Quakbot
2023-06-14KxKDrw3UhgRhcK.jsjs 879691ce61a49f015c27b523e20dcfff2e25a486bb7ee6fb24356f59235aa518Virustotal results 15.25% Quakbot
2023-06-14L1KhE2GwXpq2u1.jsjs 8b7ad482b2d4ae6336df9e63c13365e00e549e430b9a843d8a4e392a43a4d828Virustotal results 0.00% Quakbot
2023-06-14DdVMcI2DyJom.jsjs b3eca9550c45112394df705cacbe795be845f5a7ee5411f0ae9230a8bb452e55Virustotal results 15.25% Quakbot
2023-06-14KyiTMlQGp1ovqb.jsjs 7755f78d3f440e957a66b636cdcd5de8b9cbf3592c1071db582f402665ecffb6Virustotal results 15.25% Quakbot
2023-06-144YGGcDjpsNxC.jsjs 1cf12ccf2b1632da9f05834dcd311d1b703027cec1548083ee00b133e6949162Virustotal results 15.25% Quakbot
2023-06-14wP9Je5tFjtCc.jsjs 4b205ac2e0259326d144cda79838fbc8011dafb6b01c2b91cab2a0f565135e9en/a Quakbot
2023-06-14qJAxLh9D5Ir86.jsjs 989c35874bb55125bbb90a3b8c45ffc91752be59b8ed3d21be4a6a34f180b411Virustotal results 15.25% Quakbot
2023-06-14Hk3ps4STjnZYt.jsjs 2b80621d811a6d0d4b3a3439ff79280fdcbaf1dfa805fa787197cb4fa010affeVirustotal results 15.25% Quakbot
2023-06-13xq0d7hzgyeCTR.jsjs de7ba0dd3369ce72ba7adb29b44b81a557b45924516f55ffb93bc6502e35d404Virustotal results 15.52% Quakbot
2023-06-13ul55aRmIS42e.jsjs af171d05433cc6663e48cbfe0ef80633ab73d5a415889b1112d6cd62f2916517n/a 
2023-06-13VZfL5g7DMW1dB.jsjs b0cb831be2fba7c1e18dc93eabf1349f35e31cc4121678cb52996e95b6cc8e79n/aQuakbot
2023-06-13J9Ibc7dYW0yL.jsjs 36adc1c9e2bd8c45cdc4e1b0c11f8003b933601148dd8be6123d3af05ae95e84n/a Quakbot
2023-06-13LJkb4R9DC4nCdi.jsjs ec4d518f7c858f290ff5ffa938d22da0bc0955f86782578ce4e92c8526e019d7n/a Quakbot