URLhaus Database

You are currently viewing the URLhaus database entry for https://townfieldschools.com/sonn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659264
URL: https://townfieldschools.com/sonn/
URL Status:Offline
Host: townfieldschools.com
Date added:2023-06-13 16:33:22 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 16:34:36 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:2 days, 0 hours, 8 minutes Poor (down since 2023-06-15 16:43:08 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AE938_Jun_15.zipzip 35ad041d5489f5f71cf84fbe88dcf9e8c3b0b0d19788e46c0cd24c8e9e2e94d5Virustotal results 6.45% 
2023-06-15document_DE814_Jun_15.zipzip 52f20ef5d32fb2a86ebd8a8e2704585dc75f5727853829e74c728ec272761b34n/a Quakbot
2023-06-15document_DE579_Jun_15.zipzip 2514b1632b22604afe837752e9f6d6b1086a30e45f93fcc9f7cccea5c0edb8d2n/a 
2023-06-15tVRBQTRIM9ekY.jsjs 1eb702501361ad8493f11fd7bc8c0cc4894b1a0c43ef895b035a37cb2c935529n/a 
2023-06-15WsaPbup8GNo4.jsjs 0234d64b235ebab6dd2fc68d57d44282b8337113a404fac96edcdd74cefca19bVirustotal results 15.25% Quakbot
2023-06-15dg2P9YnHZUok.jsjs a7a67629ad4993b60163ed1d68260cf251bd2f265651866588464e1e52186d68Virustotal results 16.95% Quakbot
2023-06-15FuBBxawSilQn9.jsjs b5df423c6950cbaf2ab1dc9d5de5aaf55926318e7afe60838c49441dfda368a5Virustotal results 8.47% Quakbot
2023-06-14g3ieVE7461D4.jsjs 967d0effaa55efb4d57d1186b42ed722553e8eeab51d0799b03e2684a9ce134dVirustotal results 0.00% Quakbot
2023-06-149w0vsayBFm8wsV.jsjs f401d5708a2292a48b6bd517a2f3aedee2d1b4b3e4424974783b2981730cee3eVirustotal results 0.00% Quakbot
2023-06-14BOjPMFimYWIhkO.jsjs 0fa79e7800cac12dbca1636f1baca603c30a9d8564b8f4d09ba990bc216d88c6n/a Quakbot
2023-06-14docu_EF925_Jun_14.zipzip 10e566dcc281e6b991c1793ec7bb7fcf5340ff7c607fbc94780502a1567b8bc0n/a Quakbot
2023-06-14wfKurfoyoyC9f4.jsjs ba8285de74aad64490ac8de5c7f30f480041e621806ab50c68a772cc37570ebaVirustotal results 0.00% 
2023-06-14LBwdkF3na7Y2.jsjs 978259ac07ee66dcc817ab3d39ba82672a31ad51ebdfcf56024bba26859dbaeeVirustotal results 1.72% Quakbot
2023-06-14MO4L0l5oE6cCu8.jsjs b3bed41f2c986300ce7b0d623200b602f9102fa1e5fda3a14c0fd8aba9d25d90Virustotal results 0.00% Quakbot
2023-06-14nlH16rc84ERED.jsjs 9a8c247915708312d62b26f50ff7148b70745ed26a7dc1c9d9c7fc676b69d201n/a Quakbot
2023-06-14F5WaGVReLXmi1.jsjs 3dc6376b466935f3e4274c9b2512a32fbf78081607bbb34764f18674b3f487eeVirustotal results 15.79% Quakbot
2023-06-14nFX32f6cJasiB.jsjs 9b83bff8c0214c79fed588a334316494b7cdefb60f300c044dbf95f6cc37be64Virustotal results 0.00% 
2023-06-14OAjjOJzMNS084.jsjs 924f8b72bd671b4a7cb46cba011dc50137f712ba891f2ff6c71c1da0b07dd59dVirustotal results 1.72% Quakbot
2023-06-14EOj4cHTXXIKYOR.jsjs 692867b22ee80bdda8a9bb16431d65bf935fc7edb6fa326df1de95dc2c0cd66dVirustotal results 0.00% 
2023-06-147GxS5269hKg0o.jsjs 5dd98aa1f6ac0612d94036e46ff6f1fab80be4d1c4db9c1940bd5544e7b5ffd7Virustotal results 0.00% Quakbot
2023-06-14T5GOmu0bd4oOE.jsjs 8d8105af044073ca1364b0b173e3e855dbc79bd9f24f9d78ffbb17cf2a49e479Virustotal results 0.00%
2023-06-14InLKNbQzlNHTpL.jsjs 008822a7177154362dfc088ba061fa94ed7aa9fd501594345acb459375629fb4n/a Quakbot
2023-06-13vASIJDHN0xbS.jsjs 6e68ba473d14899006b97362c0d8ceb9c8443e93b7ed48bec6fc1ad0f3302448Virustotal results 0.00% Quakbot
2023-06-13OnKAUP90XCMT.jsjs e52709cccd057f0ba8a1a15af6bd3a915c79b5304a0f9ccdbd1b4b5ef32dbec0Virustotal results 0.00% Quakbot
2023-06-13ARF3SxFTNF83Mo.jsjs e803f5dd0a43fd7bbf578d9ac95b1bd433ca913ff6eb0db76824e9ae765ef877n/a Quakbot
2023-06-13S4usNuza3Kqo.jsjs 39a8756e71329bbc08f4e950ea658cd64d02c9dac58531d4c9efc0cb08f71a2dn/a
2023-06-138NBpht0CPmrJP.jsjs e67cc251b0099e6448533274e9bbee0b22390af8c47a92bb6c7fd8fbd5725285Virustotal results 0.00% Quakbot
2023-06-133RkuYa7i6ivc54.jsjs 0684acd526508b790a60181d02639f52f36ee2b2c149082a58d7a956a4a8ab98n/a Quakbot