URLhaus Database

You are currently viewing the URLhaus database entry for https://sahityaclasses.com/ciea/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645700
URL: https://sahityaclasses.com/ciea/?1
URL Status:Offline
Host: sahityaclasses.com
Date added:2023-05-30 12:09:29 UTC
Last online:2023-05-31 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 12:12:04 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 11 hours, 2 minutes Poor (down since 2023-05-31 23:14:41 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_A971_May_31.zipzip 58bea2a796185489d784100faaeb9887791f3b39fca66b330503e8b630b97478n/a Quakbot
2023-05-31doc_B683_May_31.zipzip 90d6eb7b501fea37056c2b89bd2b60e82685249ffde8bc320372631fdcd307afVirustotal results 19.35% Quakbot
2023-05-31doc_F491_May_31.zipzip d97446c62192197cfb7bc5ecc86d25c352e5591cb560e5a797356bbea9f14a94n/a Quakbot
2023-05-31doc_E087_May_31.zipzip 2c6e0e79dc783c18ddf0a822fe8acea1436d548542fe624426b75492ea1c72ffVirustotal results 22.03% Quakbot
2023-05-31doc_A274_May_31.zipzip 01d769e13e9bd1373dfd14beeddbb6f35c03e2e8fa464179665b164854cde1adn/a 
2023-05-31doc_E438_May_30.zipzip 0a3f3ee5956dd2a4b120fea50d29f8d9d62f7b17d8a63e1c0b1f4fe5d3350f12Virustotal results 19.35% Quakbot
2023-05-31doc_F258_May_30.zipzip 22215646935ef6dc589ae446d86f1a0643a31971aefc842e33edde90ef61e681Virustotal results 19.35% Quakbot
2023-05-31doc_B563_May_30.zipzip 086e5bf1f962ca10c010c055af2159621193e0eaefa47a4996eadf0f747cf383Virustotal results 20.97% Quakbot
2023-05-31doc_F130_May_30.zipzip b6f558d059e447c5432d3c59316a116e0102b12eaccf415aee5a86d94ac25c2dVirustotal results 19.35% Quakbot
2023-05-31doc_A172_May_30.zipzip 1b0ea04ad694d447297bc0def95108df0f0383762e9dce8b339e389932701be9Virustotal results 19.67% Quakbot
2023-05-31doc_B654_May_30.zipzip 3acf8cfb521fa80e65aea14f5b838fbed5af894166039c21566300f036b4b6d4Virustotal results 18.75% Quakbot
2023-05-31doc_C875_May_30.zipzip 36b000f6d8779a477dd4a5318c621277e26d83a7be92424ef66916cdb709a1a5Virustotal results 18.03% Quakbot
2023-05-30doc_A791_May_30.zipzip 81f7badd20121f186f2d4d212bce6bfb02071ae4deb981d616262de2fedc18a7Virustotal results 19.35% Quakbot
2023-05-30doc_E806_May_30.zipzip 27df250cdcf8a195c18deed15fb39b145e660cce6968af287333a180501082b4Virustotal results 19.35% Quakbot
2023-05-30doc_E651_May_30.zipzip 5b6cb9835b1f1bbccafe83c449fd94975b4268290a31bc1bb6c5dced332dae10n/a Quakbot
2023-05-30Cancellation 143326 May 30.jsjs 1cea29e090609776ecceea8ff3f35d2420a0f87f21c79c73709c9c91c690743cn/a 
2023-05-30doc_A759_May_30.zipzip f579ecc559b013afd7316b3128ce9e5f05f0b451637e9992ea97253a78c5e611n/a Quakbot
2023-05-30doc_F857_May_30.zipzip ac860f8965b254454b873295cc3b166debf4c6a706bb338bcb9b1a0ea0b30f15n/a Quakbot