URLhaus Database

You are currently viewing the URLhaus database entry for https://kncktm.edu.np/oeve/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2659435
URL: https://kncktm.edu.np/oeve/
URL Status:Offline
Host: kncktm.edu.np
Date added:2023-06-13 17:52:42 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-13 17:54:57 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 day, 22 hours, 6 minutes Poor (down since 2023-06-15 16:01:38 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_AC521_Jun_15.zipzip c9644657972919045e8f52080ec06b37bb730aadf1a11e54095459328e8b59a7Virustotal results 6.45% Quakbot
2023-06-15document_DC098_Jun_15.zipzip 92d7c371792adbd3707f2594ddbb6ec0c73ed091b27251992f743f98be774b90Virustotal results 6.56% Quakbot
2023-06-15document_CE347_Jun_15.zipzip 6211498c51cc66c1aa7d7669d5176cb6f0a1628dfccb0464d84088c1ad81a4b7n/a 
2023-06-15adudlpXH9BqOYE.jsjs 106a06ba68fab33718d88c828557ff8df114a01db94f0a854915b3773976fe9fn/a Quakbot
2023-06-15Tn2xNJXObykCI.jsjs c07705a4cb36c7eae441226475ba0b34a8fe85dd60e68fa10bfd654de40a7453n/a Quakbot
2023-06-15N4tM1hn4hGzp3d.jsjs 17a23e5494da057512e0372399cb86cc9d3a2b0d91291e7892ed6a2364dc8fc1n/a Quakbot
2023-06-15ZC9JbvZoBenF.jsjs 4887c9ed1403ae6fe007dde9ab14d02697e92bf27f84f33e41e720538853b86fVirustotal results 0.00% Quakbot
2023-06-14NzAH9nUkBMeLW.jsjs ca6c5d719c21eaf3f63c4f9b2434a3e81a8fb01345d8bb7d7bd6ba8110c39033n/a Quakbot
2023-06-148HLo8hDGAMfiHz.jsjs 5bf90545c2f31938eca16528d91721548a8394c87d3418f37a3e248246f87bfan/a Quakbot
2023-06-14r3CdaAXdSQLIk.jsjs 208cbf6ae049b69193c9aa71198bbc8db1943d0124e95d7f1c4ce75dc9be9e67n/a Quakbot
2023-06-14dmyzYUsJuwwTJm.jsjs 14778b3a1852b713cf98ab962998265809e7db541a592de80c48ac0bcb7b90e8n/a Quakbot
2023-06-14docu_EF925_Jun_14.zipzip 10e566dcc281e6b991c1793ec7bb7fcf5340ff7c607fbc94780502a1567b8bc0n/a Quakbot
2023-06-140F4lwqe3vaYa.jsjs af9a41141e77ece9fc895c1cf2c7e244f1f0f605cc25a62ddbc77fd0751cf22bVirustotal results 1.69% Quakbot
2023-06-14H8wUREWgNlZIxN.jsjs 2ebd7c581831f95264d36b567ec4a3d76f81ebb6cdb51d9a4ffc45834710ac14Virustotal results 3.39% Quakbot
2023-06-14d2rM1cvDz02x.jsjs 75030730085c9f4d5afe5987d5a00daf2c4b04fceb95ec0f241e271ee67b3714Virustotal results 17.24%Quakbot
2023-06-14NIzZQr9XTtZVzI.jsjs c3d5d8ed3d43929667664123681968458f8e57ed8eb6c2c1592b2a09db0a7575Virustotal results 15.25% Quakbot
2023-06-14DKoRV0jzlM6Q.jsjs 491b83418a174489527c074381fd93f3c09f24f279db17a8bd0953b1977680c6Virustotal results 15.52% 
2023-06-14x3Kb4Xhdgc9h.jsjs 6dc6aca3cc4c22b24664c82e847e49311fe3d52b1d0ce82b4b25e7aa876d85f1Virustotal results 0.00% Quakbot
2023-06-14Hk3ps4STjnZYt.jsjs 2b80621d811a6d0d4b3a3439ff79280fdcbaf1dfa805fa787197cb4fa010affeVirustotal results 15.25% Quakbot
2023-06-14DpwDiRPANBcV.jsjs 733f6d1e5bf6b5bc771d343e71563d881ecc120c46611d6258febdcf169eeab7Virustotal results 0.00% 
2023-06-14qFFa25W8ORzYX.jsjs 668275c132a7afc9529e007e46a89569f8c2cf5639b0d7b6549291eeec589c5cVirustotal results 0.00% Quakbot
2023-06-14poJheMfObN3ZL.jsjs 452928a08c9474e6ffe308a9952ee43ff38c8a8fcec9f14b1cd8dc5c10c9d26fVirustotal results 15.25% 
2023-06-13FgRwAInxIhktrU.jsjs 4ec6229a224c6050d9132980954acf8e230f2409a506eef5c3678a00774006b2Virustotal results 15.25% Quakbot
2023-06-13s8Qr4NnSLDwH.jsjs 3922d1b1d955cbeb3e393a4e1df563935c55fe5f545938c5a1db1a821a3c2b54n/a Quakbot
2023-06-13lGdsJjpxkhFY1d.jsjs 94623dba99508c10b256941b3006589996c4d2acf099a8ddbc711f35e71bd56en/a Quakbot
2023-06-13ehSco8ueBzmRMV.jsjs d663d679bcae514fe5d4491ad3b4e9a365452cc2b786b59a66c8ff9f72d7b239Virustotal results 0.00%Quakbot
2023-06-13LUcwiYM001Zh.jsjs efeeb808b0d33e3d59239be9ec2817abd1222228aa7122d95c78061c06923ab3n/a Quakbot