URLhaus Database

You are currently viewing the URLhaus database entry for https://stareheboyscentre.ac.ke/sir/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2661079
URL: https://stareheboyscentre.ac.ke/sir/?1
URL Status:Offline
Host: stareheboyscentre.ac.ke
Date added:2023-06-14 16:56:58 UTC
Last online:2023-06-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-06-14 17:29:05 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:22 hours, 48 minutes Good (down since 2023-06-15 16:18:03 UTC)
Tags:BB32 geofenced js Qakbot link Quakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15document_EA051_Jun_15.zipzip a7408d1b065419012f92e7999cf9cf3eebfb3e6291852937f68e2cac95f18046Virustotal results 6.45% Quakbot
2023-06-15document_EF380_Jun_15.zipzip f99aeec74ce57d9b96c141337939e7c0209b0d5bc0693f85c1109d47171aa31en/a Quakbot
2023-06-15SAxUVdcVzUHB.jsjs b4a50a421558af7eda000e4b5bd68aca11820631257692471ca3e975345c0f94Virustotal results 14.04% Quakbot
2023-06-154ks8qbGSqY2p9.jsjs a3bf7bca0993d9aff027032ff05ba404c40732ce3368909d29b039e66051a9dbVirustotal results 15.25% 
2023-06-1586n3QTz9W2fss.jsjs c568439ee7014dbc107407627c3c79eaf2b260c47a64cf0da2ed6b0debbc2578n/a Quakbot
2023-06-15HAvE2FfsM5qKN3.jsjs 08bfcc3151c4b647717d7d7ebaf3616bca9efbc76704fa45c1f547a8a9e32e07n/a Quakbot
2023-06-153aczHtl9kvSSFR.jsjs c43b65c346f4e4b646c2f07813117290ff7cc22d302d41bd24ca1af6f8ff8329Virustotal results 15.25% Quakbot
2023-06-14tgncMrgGuZH4D.jsjs 8a8c11537f0b43e6853de18f50530636afa43d84d74efa11fe7b7a97a9a4f080n/a Quakbot