URLhaus Database

You are currently viewing the URLhaus database entry for http://cdn-10049480.file.myqcloud.com/qcoin/qcoin128.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:106006
URL: http://cdn-10049480.file.myqcloud.com/qcoin/qcoin128.exe
URL Status:flame Online (spreading malware for 7 years, 5 months, 14 days, 17 hours, 36 minutes)
Host: cdn-10049480.file.myqcloud.com
Date added:2019-01-19 22:20:06 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2026-05-20 12:33:16 UTC to zhaoyz3{at}chinaunicom[dot]cn)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-06-19n/aexe 1cac63fba19ba1db24be282e292a6628f85ec86ac9e4184eeccca7400c04eadbn/a 
2019-06-16n/aexe ef0ad446de96d8c573628336ed17c8a51de5c012a6cfeff093e0417745488096n/a 
2019-06-15n/aexe cd7c1e29c472a6442c538cb13a757ba2d623ab6fd08dcef0b99fc8a49629c5c2n/a 
2019-06-15n/aexe e72a3131593f76a0b766f32ef345640ebb5e1912e81e88e36591dcf490f4fa14n/a 
2019-06-14n/aexe 0524561aca4a0c59126f622240efb4b33109233b952aa8b54a7072d1221057bbn/a 
2019-06-14n/aexe d3a675314ac367f824145772b44b67dc7c8eaa7921ead056b9e07223197f38e2n/a 
2019-01-19n/aexe 2a7b6d4238382c015fcb7e292f4f6b9c8569a49a74b793930b83d0b6c4aea279Virustotal results 48.53%