URLhaus Database

You are currently viewing the URLhaus database entry for https://evangroup.ru/bitrix/js/main/core/core.js which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3193548
URL: https://evangroup.ru/bitrix/js/main/core/core.js
URL Status:flame Online (spreading malware for 1 year, 8 month, 8 days, 7 hours, 10 minutes)
Host: evangroup.ru
Date added:2024-09-27 06:19:08 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: SanchoZZ
Abuse complaint sent (?): Yes (2024-09-27 06:20:14 UTC to abuse{at}beget[dot]ru)
Tags:js

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-14core.jsjs 0ccd07a2d22490a83c4ede78727b6bf1d522b00f18f715df9e96c06e33b6e599n/a 
2025-04-29core.jsjs 29457444b7268825b17399a00ce19fcd9ecd6647b936f229c8ca2bb35ea4ca64Virustotal results 0.00% 
2024-09-27n/ajs f7a636880bf7c2832c79f8aa7399117206e99ad1f0b5a8db1be0c4cc6a3985dcVirustotal results 25.81%