URLhaus Database

You are currently viewing the URLhaus database entry for http://45.153.242.159/44461.9891568287.dat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1640929
URL: http://45.153.242.159/44461.9891568287.dat
URL Status:Offline
Host: 45.153.242.159
Date added:2021-09-23 13:27:04 UTC
Last online:2021-09-29 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: DFNCERT
Abuse complaint sent (?): Yes (2021-09-23 13:28:07 UTC to abuse{at}combahton[dot]net)
Takedown time:6 days, 4 hours, 39 minutes Bad (down since 2021-09-29 18:07:17 UTC)
Tags:obama102 Qakbot link qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-2344461.9891568287.datdll 88a9021eecf02f1f9a661fd8f9ad080c94ceafe6d13b4eecb4502bb4a8e960f7n/a Quakbot
2021-09-2344461.9891568287.datdll 9f98c177058d1b2c3d2678887912f039595d881862bfa1fea1176c496797de20n/a Quakbot
2021-09-2344461.9891568287.datdll 48956c10fb8f6ca16af54c589fff0ceb1b73cd85d9491699bf872d9a79c610b4n/a Quakbot
2021-09-2344461.9891568287.datdll 9c8368d10ecde4d19cdf119020b3a37298cf15d8b5cef322a1b62989f3ff1ccen/a Quakbot
2021-09-2344461.9891568287.datdll fec96692c616031e36c39a58498307a1ccf96c34c4ed8f46105fbf7c2743f857n/a Quakbot
2021-09-2344461.9891568287.datdll dbbf53b95b91d68e321e5551c8a88ef3230ca525a4de1aa5e8219d4d71212f76n/aQuakbot
2021-09-2344461.9891568287.datdll b1aa64ba0c29e654ad3ce72576d0845a940f25071569f3b5472b2bbdb71c48f0n/a Quakbot