Last checked August 26, 2026 at 8:32 PM by
Gridinsoft Trust Model v2.5.3
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Retrak.co.ke
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260826203235-832972c2
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Safe
Evidence basis
First-party site analysisExternal vendor intelligence: Contradictory context — not used for this decision
The current independent first-party review supports a Safe classification for the reviewed public deployment of retrak.co.ke. A concrete LokiBot command-and-control URL genuinely existed on an older deployment in 2022, but that exact object and related historical paths now return HTTP 404, the site and hosting changed in August 2026, and fresh checks of the current root, representative pages, forms, redirects, request profiles, and scripts reproduced no harmful behavior. The conflicting broad warning was corrected; residual external blacklist and threat-intelligence records remain separately controlled historical context and did not determine this verdict.
Analyst findings
Info3
Info01
Historical LokiBot infrastructure was real and object-specific
A public malware-analysis source identifies an exact LokiBot command-and-control URL on the domain in 2022. This confirms a real historical incident rather than inferring one from a broad blacklist category, but the exact object is absent from the current deployment.
Info02
No harmful behavior reproduced on the current migrated site
Fresh supported checks, representative public pages, request-profile comparison, same-origin account forms, redirects, historical paths, and targeted script review did not reproduce the historical command-and-control object, phishing, an unrelated redirect, or executable delivery.
Info03
The broad current warning lacked a reproducible first-party basis
The current site transition is independently visible, the exact historical malicious paths return HTTP 404, and current first-party review found no harmful object. Residual provider-controlled domain labels therefore did not justify retaining the broad current Suspicious Website classification.
Review 6 documented observations
View evidence
01HTTP response
Fresh supported Gridinsoft checks reached the current HTTPS root with HTTP 200 and identified the RETRAK Home page. Direct review found no current positive behavior signal or exact malicious URL, redirect, file, payload, exploit, or hash. After the unsupported broad warning was corrected, the authoritative current report showed Safe.
HTTP status200
Final URLhttps://retrak.co.ke/
Page elementTitle: RETRAK Home
Analyst observationThe current supported review reproduced no exact malicious object or harmful behavior on the reviewed deployment.
02Content
The root and twelve representative public pages returned HTTP 200 with coherent Retail Trade Association of Kenya content covering its mandate, committee, summit, advocacy, membership, news, publications, downloads, and FAQs. Two stale menu destinations returned HTTP 404. No unrelated redirect, meta refresh, automatic executable delivery, recovery-phrase request, or current phishing object was reproduced.
Analyst observationThe root and 12 representative public content pages returned HTTP 200; two stale menu destinations returned HTTP 404.
Analyst observationThe reviewed pages consistently presented RETRAK organization, membership, advocacy, publication, and current news content.
Analyst observationNo unrelated redirect, meta refresh, automatic executable delivery, recovery-phrase request, or current phishing object was identified on the reviewed public surface.
03Form
Desktop, crawler, command-line, apex, and www requests produced identical normalized visible root content. Public Joomla login, registration, and administrator forms posted to the same site and used ordinary username, password, name, and email fields. Four site JavaScript assets and page references showed standard same-origin Joomla and page-builder behavior; no hidden credential receiver, command-launch flow, or malware-delivery code was reproduced.
Analyst observationThe normalized visible root content was identical across desktop, crawler, command-line, apex, and www request profiles.
Analyst observationThe public account forms were same-origin Joomla forms; no unrelated credential destination or hidden frame was found.
Analyst observationTargeted review of four current JavaScript assets reproduced standard same-origin site behavior and no command-launch, executable-delivery, or recovery-phrase logic.
04Historical content
AhnLab ASEC's October 2022 malware statistics identify the exact retrak.co.ke/psy/five/fre.php URL as LokiBot command-and-control infrastructure. This is a concrete historical malicious URL, not merely a domain blacklist label. The current exact URL, two related historical paths, and their language-prefixed variants now return HTTP 404. No current malware file, payload, automatic download, or payload hash was found.
Public artifact URLhttps://asec.ahnlab.com/en/41139/
Public artifact URLhttps://urlscan.io/domain/retrak.co.ke
HTTP status404
Analyst observationThe historical record names an exact LokiBot command-and-control URL; the current server no longer serves that URL or the related reviewed paths.
Analyst observationNo current malware file, payload, automatic download, or payload hash was identified.
05Historical content
Public URL-scan records show the old 102.130.122.114 deployment presenting a Bot Verification page through 2026-08-02, a different 50.6.42.29 host presenting a Coming Soon page on 2026-08-16, and the current 162.0.209.21 host presenting RETRAK Home on 2026-08-24. A Wayback capture from 2026-08-15 also preserved the Coming Soon deployment. Current DNS and the newly issued certificate match the current host transition.
Public artifact URLhttps://urlscan.io/domain/retrak.co.ke
Public artifact URLhttps://web.archive.org/web/20260815132956id_/https://retrak.co.ke/
DNS factretrak.co.ke currently resolves to 162.0.209.21 and www.retrak.co.ke is an alias of the apex.
Certificate factThe reviewed certificate covers retrak.co.ke and www.retrak.co.ke and is valid from 2026-08-22 through 2027-03-08.
Analyst observationThe public timeline independently supports a recent hosting and site transition after the historical malicious object.
06Historical content
Public OSINT separates object-level evidence from residual reputation. URLscan indexed 137 domain results and preserved the historical exact paths, while its latest record showed the current RETRAK Home deployment. OTX returned domain-level pulses tied mainly to historical LokiBot and bulk IOC collections, but zero pulses for the exact www host; its current root URL result returned HTTP 200 with no Safe Browsing match. Search-indexed public sandbox queries did not expose a current sample, and no completeness claim is made.
Public artifact URLhttps://otx.alienvault.com/indicator/domain/retrak.co.ke
Public artifact URLhttps://otx.alienvault.com/indicator/hostname/www.retrak.co.ke
Public artifact URLhttps://urlscan.io/domain/retrak.co.ke
Analyst observationThe concrete historical LokiBot URL and the residual domain-level blacklist entries are different evidence types and were assessed separately.
Analyst observationNo current search-indexed sandbox sample was identified; restricted or unindexed systems were not treated as negative proof.
Scope and limitations
The verdict applies to the publicly reachable retrak.co.ke deployment reviewed at the recorded time and does not guarantee future content.
The review did not access the private hosting filesystem, database, administrator accounts, scheduled tasks, mail server, security-product console, or server logs.
No public login or registration form was submitted, no account or credential was used, and no object was executed.
The ticket referenced an attachment, but no attachment was present in the Portal record available for this review.
Public evidence confirms an exact historical LokiBot URL but does not reconstruct every historical response or determine the complete compromise interval; restricted or unindexed sandboxes were not treated as negative proof.
We reviewed retrak.co.ke and found mostly positive signals. Current checks lean toward a legitimate, lower-risk profile, although a few caution points still keep it short of a fully verified standing. The current trust score is 89/100. Key signals include security-provider warnings, a long-term SSL certificate (7 months), and a domain age of 13.9 years. Verify key details before sharing personal information or relying on the site for important actions.
Figure 2.
Website screenshot for Retrak.co.ke.
2026-08-26 23:29:20
FAQ
Is retrak.co.ke safe?
Based on current analysis, retrak.co.ke appears to be generally safe. The final verdict also reflects manual expert review. Basic verification is still reasonable before relying on the site.
Why does retrak.co.ke look trustworthy?
Key factors include registrar information (KICHA DIGITAL LIMITED) and hosting in US. The trust score blends security detections, domain and infrastructure signals, and on-page behavior patterns. Taken together, these factors support a mostly positive trust assessment, although routine verification is still reasonable.
Retrak Digital Footprints
A structured view of the site's detected themes, page signals, and related online footprint elements.
Registration Form
Automated page analysis detected form or data-entry functionality on retrak.co.ke. Forms can involve user-submitted information, so verify ownership and privacy terms before entering data.
Joomla Platform
Our analyzer determines that this website is using Joomla CMS. This is an open-source content management system that powers around 2.6% of websites globally.
Bootstrap Framework
retrak.co.ke uses Bootstrap, a widely-adopted open-source framework for responsive web development. Bootstrap enables efficient creation of mobile-friendly interfaces through standardized components and styling.
jQuery Library
Alpine.js Framework
Animate.css Framework
Social Media Links
The presence of social media links on the website indicates that it references social media accounts. This signal alone does not confirm ownership or authenticity of those profiles.
Long Term SSL Certificate
The SSL certificate for this site is valid for more than 6 months, indicating a long-term commitment to security and trust.
Established Domain
retrak.co.ke has maintained active domain presence over time, indicating operational continuity.
Verified X Profile
Ownership verification confirms that this site controls the X profile @retrakenya (RETRAK Kenya) (1,309 followers, 463 following, 2,412 posts, listed 21 times, since 2015, blue badge, location: Nairobi, Kenya).
External provider warnings: 11/29
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
ADMINUSLabs
Malicious
Antiy-AVL
Malicious
Chong Lua Dao
Malicious
CyRadar
Phishing
ESET
Phishing
G-Data
Phishing
Lionic
Phishing
Sophos
Phishing
VIPRE
Malware
Webroot
Malicious
BitDefender
Warned
External provider results for Retrak.co.ke, last checked August 26, 2026.
— VirusTotal
Domain Information
CreatedOctober 4, 2012 at 9:40 AMUpdated: August 22, 2026 at 4:24 AM · Expires: October 4, 2026 at 9:40 AM
If you own Retrak.co.ke and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about retrak.co.ke, the fewer chances they have to deceive someone else.Help others evaluate retrak.co.ke by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about retrak.co.ke, the fewer chances they have to deceive someone else. Help others evaluate retrak.co.ke by sharing this page on social media!