URLhaus Database

You are currently viewing the URLhaus database entry for https://kianco.com.ng/pv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660025
URL: https://kianco.com.ng/pv/
URL Status:Offline
Host: kianco.com.ng
Date added:2023-06-14 09:02:20 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:04:18 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 6 hours, 46 minutes Poor (down since 2023-06-15 15:51:03 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BC692_Jun_15.zipzip 15f48fc6399aeda7caab8d02aa81982750deb73c3851dc4b366814ec2bbe35a6Virustotal results 6.45% Quakbot
2023-06-15document_AC231_Jun_15.zipzip 94e365a2799a5d2e779c7feef08abdec0bd766781b439416f9dabad935581fd1n/a Quakbot
2023-06-155yKZLBmRy9v1Kw.jsjs 2361d8d93137a10c521d989a2d0c61b0af2fadf429598dd3a21874e4002aff1bn/a Quakbot
2023-06-15BFBC0J0XzxDpo.jsjs 9ccbc2c2242925af928a76775ff4a4797207e9aed9e77cd9146db9e5541ab35dVirustotal results 17.24% Quakbot
2023-06-15upErIflJcu8vY.jsjs ec04972b62c7083c2ad7622fd19ed2e797a2066d662562c8f1ee2ec53572c9d7n/a Quakbot
2023-06-15Evbhr4KJz4Ruap.jsjs fd450cc9d3bc06782edac878682ba7850a42fb1a083c18564f722aab22534d8fVirustotal results 15.25% Quakbot
2023-06-155T00wO7fyjAP.jsjs 4b559415bcf3a2d3a2282b5b52378fc6011490efb026c90a3eaf22008c669ef5Virustotal results 3.45% Quakbot
2023-06-14NCdC96ZjN66V.jsjs d63c4cae8c53be6652aa7f640c86934c7b817331624488a1a1d08ee05212b37fn/a Quakbot
2023-06-14yFMBrk40cjBRe.jsjs a0232a8d0baf4d0920db8601ec87245d603c6fd3ef6f65ab4f9a7eb7144fe7e7Virustotal results 0.00% Quakbot
2023-06-14DJJ7rHqrbmykL.jsjs dbba63c88e0fb3b01ae4b4023e3764c2ba6f6b9f2eb506ef4b3c6753a998952an/a 
2023-06-14RFAPF4c7ZlcF.jsjs ace7e54ad918b9e0d402b739f428fc4ab0e95c43b528047136339fac1caca828Virustotal results 0.00%Quakbot
2023-06-14fJpJgHXpXurtyr.jsjs d072ce279b63835641a7bff67341e69ec7878a73f9b5e4223969fdff81a0cb51Virustotal results 17.24%Quakbot
2023-06-14V30iJezZFCjXX.jsjs ccca70bc38f9c4f8832482f515ab6bb37f2d6fc7e459cb5114768bf05f378f96Virustotal results 0.00%Quakbot