URLhaus Database

You are currently viewing the URLhaus database entry for https://kenkostationery.com/soq/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2634016
URL: https://kenkostationery.com/soq/?1
URL Status:Offline
Host: kenkostationery.com
Date added:2023-05-16 13:14:56 UTC
Last online:2023-05-18 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-16 13:18:08 UTC to abuse{at}bluehost[dot]com)
Takedown time:2 days, 8 hours, 50 minutes Poor (down since 2023-05-18 22:08:49 UTC)
Tags:BB28 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-18Jrtvrtmh.jsjs 1cea0c4b1af9170b9ed2927f3b100d202bebd1b8e69ba1527336aaa6b2c0bffcVirustotal results 13.33%
2023-05-18Hqqxn.jsjs 1a2e818afb29521c8658d2a0643158af97370d69c32c0bd85cb900bd3e85b0eeVirustotal results 22.03% 
2023-05-18Wgiaoq.jsjs c74cf0cb7927a8438a84c9cedbdbab3e4815550813336043f39674a67b6a021aVirustotal results 28.07% 
2023-05-18Dqyob.jsjs 361485c0240c2c07ea383cda8cb6e0e0bc30d7b953ccc2e213d3a74adcee5686n/a 
2023-05-18Cuiv.jsjs 72495f905e654ea365738e7e3ac93200be27ad81df4327197c8d1a1427209a25n/a Quakbot
2023-05-18Etjmi.jsjs e4e514b57ab086485b47e1413c71a7e9bebc8c84c6615f90bf252d04c98fb5ebn/a Quakbot
2023-05-18Txex.jsjs 72c9727d22512473f4aa27d93e0c15ae33a95784d9804b057275d0d7d8b0a361Virustotal results 8.62% Quakbot
2023-05-18Jacxjn.jsjs b65cfc5c1f188f590ab7d7d6a20d1ea638a086a9be61e3442b6ea9388fda3c0cn/a Quakbot
2023-05-18Buqr.jsjs 60ac01b6dc615a190d4fd5f4ae9e67d29d9faf9784d997dc375bf3bc5affcbe6Virustotal results 30.19% Quakbot
2023-05-18Wfawnlgk.jsjs 4c15dba778afb1200f2c6d840c81c397c3fa416e7e47b19d01800000c0ce6f82n/a Quakbot
2023-05-18Hweu.jsjs f0dbb6e29c6d7e8d5463a1e716423776b0aa2be9fedbdd957adf165559ca8a5dVirustotal results 28.30% 
2023-05-18Fdosnmpy.jsjs 08b43f87f3dd81d9be92cb99ab4547399f67348b7ffe33011b49947b98a44046n/a Quakbot
2023-05-18Cdqu.jsjs 0e8413c3fd2b87cd2139ba54c718d6b9f305a8bf33d41f05aaaa2639ccde842cn/a Quakbot
2023-05-17Ypazc.jsjs ed4b4009ba340ee9369058f34b9f50d2cb0057933fa2033412123538dd6093ecn/a Quakbot
2023-05-17Dttg.jsjs 9aa3958dd376fcd792957165b53999bc05bdb411a0ea61e30b7787e1a7cdfbf0n/a Quakbot
2023-05-17Dgiuiout.jsjs 7aabd12a63a4289e6a5f5fc62d866ed2ade8e917a6f2d203bdfd37c0f87ab265n/a Quakbot
2023-05-17Qdxonmf.jsjs ed3b42a466d5debc63224e8439d69996fd4f174cfcae800ac31dd8dcb69c921dVirustotal results 31.58% Quakbot
2023-05-17Vllbotpc.jsjs 2148fe2b647b8aa1006957e65de07d42e631ced18a21aa3d1aef1ad5d22ffae2Virustotal results 29.82% Quakbot
2023-05-17Ancukvml.jsjs 2b2ddaf766a72a62c3247e520317d64f6b32231d8802b99b861cdbcd872a7ef0n/a Quakbot
2023-05-17Ooaqdh.jsjs b2e23c529e80dabc306726c89dd843df4bc84130430fb22df8bdfd18d9e91035n/a 
2023-05-17Kmseerzo.jsjs 9c12ea99cd0976f6e12ad925b7b295ca97ac6b79c95874c261b5a30367ef56fan/a Quakbot
2023-05-17Cpuvaf.jsjs bc32b92a572a48f536e0040615869a4f0f689d1fb6fb939ea0c431cb85c05157n/a Quakbot
2023-05-17Yuoi.jsjs 1cd067d9dd98015c13356c5dd84dac73ffe64b73aadc6d443c2b61617f12e357n/a Quakbot
2023-05-17Spzs.jsjs 968d59ac2ed236b54ade1d292e21c2812bd5d418e188ae4714f5eb7efa84a206n/a Quakbot
2023-05-17Ciwwac.jsjs 3da017c63ee5eebb3263b1595197809ae943753cac6c84869beaa9089b1b9699n/a Quakbot
2023-05-17Ddymyz.jsjs 9acdabf6f55d9173330b18e696e23b14293bacd39de73e4262170398e205aa3fn/a Quakbot
2023-05-17Mevgnznc.jsjs a37b2d9d710500f277fdd61c545b43395e29a678068817f22f4cfd546de1bd47n/a Quakbot
2023-05-17Iiigpxva.jsjs 0e55e6beda9184ea83bc986313963310de8af2e342d268f82521ec60254b09ben/a Quakbot
2023-05-16Sxenh.jsjs 3edc7aff486313b595fdfc0171e0982df0df3a14aca47b53a7f834896c07042fn/a Quakbot
2023-05-16Onisour.jsjs 480b11234fe40849683090197f2de1d54b21e8d3b2502dadd168325b563f0d84n/a Quakbot
2023-05-16Vdnwjve.jsjs 8516cfe162859eafe451796e611180f658d0483332be8ec9faecd6b37c7fbc5fn/a Quakbot
2023-05-16Xagomta.jsjs d36f911852c4f0f4f03d1d7407de8bcf5254c46d2338df76320135f3aac22111n/a Quakbot
2023-05-16Sviex.jsjs 49fd7249eb2b882b57b67c07b1f90fea2f08d4a051ab3d753c21c4c5827c6fb8n/a 
2023-05-16Bxzii.jsjs 2277f8c462b346bde38f11c0d625852514543be06b5f5a992db7e6c26e1ee68dn/a Quakbot