URLhaus Database

You are currently viewing the URLhaus database entry for http://49.234.48.162/pdd_biaoge/soft/down.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3236224
URL: http://49.234.48.162/pdd_biaoge/soft/down.exe
URL Status:flame Online (spreading malware for 1 year, 7 month, 18 days, 22 hours, 4 minutes)
Host: 49.234.48.162
Date added:2024-10-15 15:26:17 UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-10-15 15:27:18 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-09down.exeexe 1f23339dd3a2f2548c2ebc00e2ef1247cdd38f63692806d2c830462f297ea37en/a 
2025-04-08down.exeexe 389fbaffbe7e6c7de6935e634ac3ef33a642ad49cf4473f828fd777ff2159fb4n/a 
2024-11-04n/aexe 717c75dcbd4862e3f5c1a744fc445385bd7b920496988b3759ee6a47b5d3e080n/a 
2024-11-03n/aexe 95629c41800a20a6f760a7412a312ecc8b0d8e956a353b11968329bb74262567n/a 
2024-10-31n/aexe b84b12557d98e90362501215f1289d8cb66d43e92f9f0a3d5d19a75dffc0a23dVirustotal results 52.86% 
2024-10-31n/aexe 0dfb5d7a191fb5b7bd75953926446c41c36f6c0133f3aa85d1109a3389d9aea3n/a 
2024-10-31n/aexe 0abf94f7559692cba19941851d767d4bedcd4326fb59f8bf87f7bed7f2012e12n/a 
2024-10-15n/aexe 77a53280fd609c5594c6f78453ca8468dc4d0305c87293655b85a50f88681792Virustotal results 64.29%