URLhaus Database

You are currently viewing the URLhaus database entry for https://zambianroadsafety.org/ed/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2646593
URL: https://zambianroadsafety.org/ed/?1
URL Status:Offline
Host: zambianroadsafety.org
Date added:2023-05-30 16:51:15 UTC
Last online:2023-05-31 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-30 16:54:40 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 2 hours, 34 minutes Poor (down since 2023-05-31 19:29:18 UTC)
Tags:BB30 geofenced js Qakbot link Quakbot link USA zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-31doc_C072_May_31.zipzip 90cb9a80f2fb095bf7e4411273f5c1f471abc052235d274667fbb9d85c540225n/a Quakbot
2023-05-31doc_A459_May_31.zipzip 7967e54a6bec438b212e873903b8efa62d2431b4671e9dd54bc1ba027fd239e4n/a Quakbot
2023-05-31doc_A619_May_31.zipzip 2ace79b23b23e556769eff8a564647dbab903f8e2538b43554b7bfb30713824cn/a Quakbot
2023-05-31doc_B326_May_30.zipzip 5117fdc1a4b1e96d25d904b426f5fa25e56c9d8ba63a29e472a233164a801a4aVirustotal results 19.35% Quakbot
2023-05-31doc_A167_May_30.zipzip 43c61ea77a650758ed9b451bb7fb2b44c61c7b9ad33c337d0f7ddb7a491c80d3Virustotal results 19.35% Quakbot
2023-05-31doc_E509_May_30.zipzip cf406b4ea3a25ae0b6406eb130de17213a40ed3f0b185cc99ee79573a86b553fVirustotal results 17.74% Quakbot
2023-05-30doc_B089_May_30.zipzip 2a338789f03ebf32fa9ec69c8356ef688fb9ea1774ef74c234dc64dd01f2f073n/a Quakbot