URLhaus Database

You are currently viewing the URLhaus database entry for https://obckitengela.co.ke/atu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2660059
URL: https://obckitengela.co.ke/atu/
URL Status:Offline
Host: obckitengela.co.ke
Date added:2023-06-14 09:02:25 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 09:05:01 UTC to abuse{at}ioflood[dot]com)
Takedown time:1 day, 7 hours, 7 minutes Poor (down since 2023-06-15 16:12:32 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_FB759_Jun_15.zipzip 3dfeb6231162f5265209622dfa7d577e12cd351945ef90e96afb96f33f86aa23Virustotal results 6.67% Quakbot
2023-06-15document_AF846_Jun_15.zipzip 92f95f3c5faba8fc604467b725de06b9e3ab98d53d23c89fae671737673509ddn/a Quakbot
2023-06-15pEyYgmOfSrjk.jsjs 8b5a82fa609d50c0a468ff020ca341705079306871bce90a0451e263f7b8016cn/a Quakbot
2023-06-15KFLpaYUVAtzMr.jsjs e012c33067126a3eaf000a93ef4fa8d4b57ab9fc4c4709431c6f68f0f5d39422n/a Quakbot
2023-06-15oPYMx8rtUQ8O.jsjs 0703c6fdd8f57392a6e5c1c1ab1976cf323ef46e5c6d37c9724dedc3f1279c15Virustotal results 0.00% Quakbot
2023-06-14toTCZhheAXTS.jsjs a822a6eafdbf9a61dfe157928f2b1c3188911779912b1b3042eb1e275fc632cbn/a Quakbot
2023-06-14J2WMpdDtgVeK.jsjs 151c588068eae141a0db50feefcc992b95863963a34965674fd7c93150e633d5Virustotal results 0.00% Quakbot
2023-06-14BE28yv9HINumi.jsjs f32241257a07f745df905972c8093d7b1de476b2564f694dd973fbff41037053n/a Quakbot
2023-06-14docu_AF913_Jun_14.zipzip e0c2a085c8114d507dfba0938ef61d878d75cbdf6e18cc681bd736f92b72fb34n/a Quakbot
2023-06-14MTCQEHycHaN3sK.jsjs 61cfe8e85215a8333a55777c1477bff67ac515129ba324a6df6180f7e3e5856eVirustotal results 1.69% Quakbot
2023-06-14WHtlC60PAY5NvF.jsjs 7074ff624519388df3fce38a20a1ce34aad2d8b620c5e61c13b7443ebd572b7eVirustotal results 0.00%Quakbot