URLhaus Database

You are currently viewing the URLhaus database entry for http://124.223.105.161:8902/files/data/drss/drbw.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3561839
URL: http://124.223.105.161:8902/files/data/drss/drbw.zip
URL Status:flame Online (spreading malware for 11 months, 18 days, 1 hours, 43 minutes)
Host: 124.223.105.161
Date added:2025-06-13 12:32:08 UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-06-13 12:33:09 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-20drbw.zipzip bf7ab6e8e9dc2013c179286a89b04ddef06aa2e6bb52249443975ef930815226n/a 
2025-07-18drbw.zipzip 34e6b320a46dfb80972c09af67c463c0abe8c525e863df66b7cb111a1157181fn/a 
2025-06-13drbw.zipzip 1c20b223d758502ace11f216a89a2897a61118de7b0cc6578da9a1116709f5b3n/a