URLhaus Database

You are currently viewing the URLhaus database entry for http://23.249.161.109/chfrd/qsr.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:36410
URL: http://23.249.161.109/chfrd/qsr.exe
URL Status:Offline
Host: 23.249.161.109
Date added:2018-07-27 11:05:05 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Unknown
SURBL:Not listed
Reporter:@JAMESWT_MHT
Abuse complaint sent (?): Yes (2018-07-27 11:09:22 UTC to support{at}vpsace[dot]com)
Tags:quasar rat link QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-08-14n/aexe 49b4e1dec55e49cd46daf7f69ccd33038d9b69b52b7ccf4808a36363413c6b2cn/aQuasarRAT
2018-08-13n/aexe 30506a7332c8c862297acbf112d4cbf43b5f359ff83f0b7c142512f17de4e78fn/a
2018-08-02n/aexe 2b2314c8a255a08803fc37ca56261c50230772843b2a7bd977bc2bab5d7b8fa3n/aQuasarRAT
2018-07-27n/aexe 96773d72020b2aeaecd3b4ee476e996e5ecf73a14fc12fc712b7de971dae8e3dVirustotal results 20.90%