URLhaus Database

You are currently viewing the URLhaus database entry for https://qeextension.com/777444777.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2295927
URL: https://qeextension.com/777444777.exe
URL Status:Offline
Host: qeextension.com
Date added:2022-09-07 10:16:07 UTC
Last online:2023-02-28 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-09-07 10:17:08 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:5 months, 23 days, 19 hours, 46 minutes Bad (down since 2023-02-28 06:03:40 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-08n/aexe e1b785c144442dccc51ae3738420fb72cf83117133dbd4e8816c3205492a7845n/a RedLineStealer
2022-09-08n/aexe 1929bc7dcec66003f5c4783d0e5e5fcb3a8523562e21235ae778956da9a76014n/a RedLineStealer
2022-09-08n/aexe bd68e7268eff3e77ba4c500b22d8c9dc608be8280bff106039b0d65f37b3750an/a RedLineStealer
2022-09-08n/aexe 735328a34d7b6405dd4f2d245156496afa0a484353320939fe89d8cef7ddba40n/a RedLineStealer
2022-09-08n/aexe 3b87ff533946d35e36b361161da82504e788b96fe61a27616f3426a8ff1c2d84Virustotal results 38.03%RedLineStealer
2022-09-07n/aexe b73d9776ce79f7e01e8892fa9053e6459b0ce682167b4e24f2b7f9504572c4ban/a RedLineStealer
2022-09-07n/aexe 4be799434f37c35a47d9fd1d901f96c3bc2976da692393e6a42c1ecf6a919143n/a RedLineStealer
2022-09-07n/aexe 9a69d3fe71b919383bee912449afdc5decbe41077bd8cb93e4a4190447c80dc7n/aRedLineStealer
2022-09-07n/aexe 6e875f8f6277e5fec0f23f982c7d2dbc730408f10353053f19aa3e0ed2e2ea06n/aRedLineStealer