URLhaus Database

You are currently viewing the URLhaus database entry for https://stareheboyscentre.ac.ke/dsi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659377
URL: https://stareheboyscentre.ac.ke/dsi/
URL Status:Offline
Host: stareheboyscentre.ac.ke
Date added:2023-06-13 17:52:24 UTC
Last online:2023-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:53:53 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:1 day, 22 hours, 0 minutes Poor (down since 2023-06-15 15:54:26 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_BF245_Jun_15.zipzip b4ab0caa12b99e004f6f9e3e2ded8de95420ce9825660ce0e20b40a34da98b08n/a Quakbot
2023-06-15document_BC714_Jun_15.zipzip c4daec3c35b73ecbdd3ca7ae117b8843fbfc8742b7bd409cf96b34c64348693fn/a Quakbot
2023-06-152QEYfuIo91cn.jsjs 5acb9a486b057ca3443f9e2d124dd4d2edfd02830accc5fbf4c35d556dbc99adn/a Quakbot
2023-06-15PAExFZAovQBa8.jsjs cd2e43cf08dd4395275266cd91c3af5adcaee3658abdc7543c8ad2e3aae800d7Virustotal results 18.64% 
2023-06-15pynRokyXEFIXG9.jsjs e489f835044f88c08f032bd19e030b0c4c1de0c10cbd5dd8aa9f535056604724n/a Quakbot
2023-06-15DAQ4xweAxYlq.jsjs 4eb99516b8ffaa707236803c38a58a4667cbd8de06ca59da2cd6d2ccd9dd29b2Virustotal results 0.00% Quakbot
2023-06-152DaaxOKctyjx0.jsjs c020b80a4b247dc41cb9f9dae71a6a597c42a0388eb6eb730bc3c0b16e03e621Virustotal results 16.95% Quakbot
2023-06-14Tqd4xng0OXL6P8.jsjs a8fd740eec8fd7054cf5296b67f9f6bf45117dd13bd1fe911003d146bc139365Virustotal results 0.00% Quakbot
2023-06-14nS8sLQi0fi36NE.jsjs ca5c309d96102ebf5f5971d73782cb98259c7c5eb51e66eacdc132c164f3ba11Virustotal results 0.00% Quakbot
2023-06-14EKQrmyk8jpK6.jsjs 8c67f76ce9c1f02e2081111bafdde75ec020bcd302ceebc22054b2ff8cf4d1ecn/a Quakbot
2023-06-14docu_ED627_Jun_14.zipzip a8fa341a4092c92e4dc493a747766e8726c2c92d4c7a894a7044040df441d369n/a Quakbot
2023-06-14vWnfDG4oMUlf.jsjs cef236290fce0aa372364acacef0e4d551963d3a3774df2a383c222069ee6fbeVirustotal results 0.00% Quakbot
2023-06-14JhAxqGz5OxLW7.jsjs f666a788127bf2f9889af7487b05343a3bd70aac5e1422f3d072c6c7a2f5f1ebVirustotal results 0.00% Quakbot
2023-06-14I7Vsj6yOmGZT.jsjs ac30912298480d45bf0f9e1c035e96da5c56cda83c13d501510cf812d0e8d113Virustotal results 0.00% Quakbot
2023-06-14a8mWJb4hQSSAc.jsjs cea0787fe709eb7bd1f4572d915f64c70f3fb2d0467373885c3f452c7b7064f7Virustotal results 15.25%Quakbot
2023-06-14aOEkRE2A2Uyx.jsjs abea42c24e68ab1dfce9c66e1d510c5a7fb59c47ebfce07b2108bfa4829dea83Virustotal results 0.00% Quakbot
2023-06-14Ep51bPwAOhqhr.jsjs 753a12f4c48117a93c5e870258ba0c96381bf2681fb1837ac826f913f6ee0a83Virustotal results 0.00% Quakbot
2023-06-14oZhWiM2lNRCdN.jsjs 8fc167cc73d786af01b05a9fd666d2c6f1d30876de212c419cabb127bb8166e1Virustotal results 15.25% Quakbot
2023-06-14fOV0hSWDyHeW.jsjs b6a5500d74194a37da84437b133a789b7fa7b6cbbd3cafc4663cebeda05abac3n/aQuakbot
2023-06-14RF6RkjbXoHHSH.jsjs cb3e1f933184aa926916c16ca694a0999fe40084d1e5c337e8701a14e1945398Virustotal results 0.00%Quakbot
2023-06-148nqEEGz7A7nVE.jsjs 91f627516bba65bcf752f5fa9eae092d7e3ff81267bd5ff6e7acabcc6eb8425bn/a Quakbot
2023-06-14a4YQ6UxZhsp5tr.jsjs c1f1fbad43a84d906bfce43674da268bad184919e8ee6d7a1b903f4270576f79Virustotal results 0.00% 
2023-06-13B2BnZLFK0PBhRi.jsjs 4304e41f662e2f2d1daf566caa548a3dd07c92147deee4e71ef1ab7028e2d723n/a Quakbot
2023-06-13xNqqQkfYnlavf.jsjs e98179ba26166bab10a3785f30b1a5d43584f92e340546d0a379ca0607157aa0Virustotal results 0.00% 
2023-06-13GydMf1FaNMbCP.jsjs bbfb0ba41ca93c14c1ce9a65464fbee472fb0f2eab52dc47eac07d2ff59ed4b2Virustotal results 15.25% Quakbot
2023-06-13aRK7IDigp9Ikkr.jsjs 40e01e9ddf622b2a881300df56b228572e8c206a15b9ae8f94c0e50f11dd74a9n/a 
2023-06-13HY3IpdZj7TXhkE.jsjs d5f421958a886120250e24c76c85bb73298c77778130eeb5b72341566f98bdd0n/a Quakbot