URLhaus Database

You are currently viewing the URLhaus database entry for http://111.90.148.104/44466.4604863426.dat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1645670
URL: http://111.90.148.104/44466.4604863426.dat
URL Status:Offline
Host: 111.90.148.104
Date added:2021-09-27 16:07:04 UTC
Last online:2021-09-27 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: nokae8
Abuse complaint sent (?): Yes (2021-09-27 16:14:02 UTC to abuse{at}shinjiru[dot]com[dot]my)
Takedown time:44 minutes Wow (down since 2021-09-27 16:58:33 UTC)
Tags:obama103 Qakbot link qbot link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-2744466.4604863426.datdll 147b0aaa69f70f9b83b1924debaed93e3e27899ec406cee7fd89484dc71a5af7Virustotal results 37.88% Quakbot
2021-09-2744466.4604863426.datdll aee3ebf75436b7386e0dd5fa7f1b6a4fd63cc8a2b1211e2c048477d8d28c0b46Virustotal results 44.78% Quakbot
2021-09-2744466.4604863426.datdll 92bbfcf3d6f01b31992a0a15d4d0762548f983783f418bac75b67f93fdd5b05fVirustotal results 10.45% Quakbot