URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: qeextension.com
Domain registrar:GoDaddy -
Domain registration date:2022-02-01 23:28:20 UTC
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2022-09-07 10:16:04 UTC
Total malware sites :3
Online malware sites :0 (0%)
Offline Malware sites :3 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-09-07 10:16:07 85.187.128.60sg1-ts103.a2hosting.comNot listedAS55293 A2HOSTING- SGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-09-07 10:16:07https://qeextension.com/777444777.exeOfflineexe RedLineStealer ext abuse_ch
2022-09-07 10:16:07https://qeextension.com/3.exeOfflineexe RedLineStealer ext abuse_ch
2022-09-07 10:16:07https://qeextension.com/jasper.exeOfflineArkeiStealer ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-09-08 11:41:245d243ded181eefcd0d051a13f2ba7845223b576d6c8f93777552cf252e28bc90exeRedLineStealer
2022-09-08 11:13:17e1b785c144442dccc51ae3738420fb72cf83117133dbd4e8816c3205492a7845exe RedLineStealer
2022-09-08 11:07:443b275eb3041764efa0c25789652714f73013eba1cca9636d1dd201db733e16c1exeArkeiStealer
2022-09-08 11:02:071929bc7dcec66003f5c4783d0e5e5fcb3a8523562e21235ae778956da9a76014exe RedLineStealer
2022-09-08 08:25:10002d0341d1c38f40a8b28fba9fdc37146cff0fc81c7850400a31da1d7a5ded9bexe ArkeiStealer
2022-09-08 08:24:27bd68e7268eff3e77ba4c500b22d8c9dc608be8280bff106039b0d65f37b3750aexe RedLineStealer
2022-09-08 08:23:242cfc599ed129c7805a74b57c6b4361e02e5f5f442ecacb2bde327791154575f5exe RedLineStealer
2022-09-08 04:32:37735328a34d7b6405dd4f2d245156496afa0a484353320939fe89d8cef7ddba40exe RedLineStealer
2022-09-08 04:20:54790bdf75b81fe64f7f100c9ac7622f311d78fa785e55fd27849013685d7f5ebeexe ArkeiStealer
2022-09-08 04:20:54d8992ebf7ac783376aa06ad641739c80fc63de6f44962d05c6e16683a638a1e1exe RedLineStealer
2022-09-08 01:26:36f7ef499a27740ce9242dae6005defb9b553fa0d56248e3d22838beb5a1733cd0exe RedLineStealer
2022-09-08 00:46:243b87ff533946d35e36b361161da82504e788b96fe61a27616f3426a8ff1c2d84exeRedLineStealer
2022-09-08 00:44:4155bcbf0961f5e9dd1b6dbb80ecdaf800c5160951a40e11dda75e54b953233df7exe ArkeiStealer
2022-09-07 20:28:27263ff33c64bd366c48a308be2591b7e6157da9dcbfed83393ea1a3eebb7ca12aexe RedLineStealer
2022-09-07 20:21:29b73d9776ce79f7e01e8892fa9053e6459b0ce682167b4e24f2b7f9504572c4baexe RedLineStealer
2022-09-07 20:08:109bdf483babcd977ed8995ddd16552b29343d829521fb54a2a6e8858cf8800d0cexe ArkeiStealer
2022-09-07 16:35:468f0a66a28b150d0d3900c165fbcafea5f56297ffda036b64a4f57703a36ce64fexe ArkeiStealer
2022-09-07 16:10:18170eae65c4a82f62b0aa21add0155f0453d927c1dd2e9e6a2b6f4437c9dd523aexe RedLineStealer
2022-09-07 16:09:354be799434f37c35a47d9fd1d901f96c3bc2976da692393e6a42c1ecf6a919143exe RedLineStealer
2022-09-07 12:16:3847581e7daf7e92fa4de9fdff4e7b055ca5c80a34656823aa4034a02c39390bbcexeArkeiStealer
2022-09-07 12:12:549a69d3fe71b919383bee912449afdc5decbe41077bd8cb93e4a4190447c80dc7exeRedLineStealer
2022-09-07 12:08:4435e4a3a37c4ea7a57d865d675bd7623b933fdc9dde9f7da486805e958bef0aeaexeRedLineStealer
2022-09-07 10:16:076e875f8f6277e5fec0f23f982c7d2dbc730408f10353053f19aa3e0ed2e2ea06exeRedLineStealer
2022-09-07 10:16:07eaebbcfabf1e0beb840eec09eb14cd178a003964246ccb43e523169f9403ee2bexeArkeiStealer
2022-09-07 10:16:07f1ff1f2a244a1592b60d79ac236be7acc6f6ca00fb794700caf6002cd20b6617exeRedLineStealer