URLhaus Database

You are currently viewing the URLhaus database entry for http://ddl8.data.hu/get/221922/13065087/QS.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1705795
URL: http://ddl8.data.hu/get/221922/13065087/QS.exe
URL Status:Offline
Host: ddl8.data.hu
Date added:2021-10-21 18:12:13 UTC
Last online:2022-01-07 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-07 07:24:40 UTC to abuse{at}telekom[dot]hu)
Takedown time:1 year, 3 month, 6 days, 19 hours, 15 minutes Bad (down since 2023-01-21 13:28:37 UTC)
Tags:AsyncRAT link bitrat link exe rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-08QS.exeexe 8045410ac9cffa3405577c5da67b16d897ecbd43912ab5af96e48df007a4b87bn/a 
2021-11-07QS.exeexe 209ac2e4de0e9567dfbef538890b5fbd5aa2d2b940fc706245f343225dcb8ae4n/a 
2021-10-31QS.exeexe e5538b9fe4a8a69e5c51d173144edae8bcd8f4739cb265f9a9d5efb15fd1af1en/a
2021-10-21QS.exeexe 7fcb98579512e3df028c8199b530d8e027d55a871d2afb81aeb5994adac814bfVirustotal results 53.73%BitRAT