URLhaus Database

You are currently viewing the URLhaus database entry for https://xdframework.com/ps/qbot.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2396295
URL: https://xdframework.com/ps/qbot.zip
URL Status:Offline
Host: xdframework.com
Date added:2022-11-02 01:59:20 UTC
Last online:2022-11-24 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-02 02:06:25 UTC to abuse{at}register[dot]it)
Takedown time:22 days, 10 hours, 18 minutes Bad (down since 2022-11-24 12:25:12 UTC)
Tags:BB05 BV1 iso Qakbot link qbot link Quakbot link TR zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-15Tail7.zipzip f291bf72225652955326ed7b1cd5f1893b12d55ea8dbd9b471bf7497b97211bcn/a 
2022-11-15Pdf8.zipzip f71da5d36642a5955cc60c6a7c0d0d31b160b5f718e7556cf8947600fe67c557Virustotal results 0.00% 
2022-11-14k7.zipzip bbafd280d8ff9b0c3f4c0eb9edfd9561922c2bf7262aee2c878100e102d57ba0Virustotal results 3.12% 
2022-11-10D9.zipzip 59246a44acfb1b0100c35bbed657fd29d3d7f33bdd9b777100f3f7a22b695cf5Virustotal results 4.69% 
2022-11-08D5.zipzip d6663936b3c67a05dc7436ebf914ef582cd3916ad853a9aa0e22245aabe898b3Virustotal results 1.61% 
2022-11-02IT8.zipzip 93a565b52990e61a9baf0660aa9a7b961694cf8d292f8c706cfb1b56a1265678Virustotal results 3.23%