URLhaus Database

You are currently viewing the URLhaus database entry for http://pay.aqiu6.com/autoup/Client/AQClient.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:66694
URL: http://pay.aqiu6.com/autoup/Client/AQClient.exe
URL Status:flame Online (spreading malware for 7 years, 8 months, 25 days, 18 hours, 1 minutes)
Host: pay.aqiu6.com
Date added:2018-10-11 06:26:14 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2025-05-06 23:33:08 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-06AQClient.exeexe 30fa4904cc2616a1b81f5baa3accfabc8d6a4f857cd69922ce00788c2927002fVirustotal results 55.88% 
2020-04-15n/aexe 0afc026d81a209d2b048c70e87eb7d4f0fdc84024565d44d67b0b4a235b3f454n/a 
2020-01-21n/aexe 6d10276547d261878cfd679ca39743101acb4fad711e6b0445a52c617a0b2950Virustotal results 67.65% 
2019-01-25n/aexe c20f27d9350cf01cf5fc0ee50d79fe4bf73e99882cf67d07fd35890cc4c45264n/a 
2018-11-28n/aexe b13cc94c998f522cef00102d245f106901254227adbd92bf65f1f334162c37b8Virustotal results 8.96% 
2018-11-25n/aexe d0347b9f06efc34fc243e87bd34356ebe5dada37d872970b1e928a08be6bb74bVirustotal results 10.14% 
2018-11-15n/aexe f0bf3f1f20cbfd28aebc298897b09fc8cb9aa95448067b6717bed4bc0f9b8b50n/a 
2018-11-13n/aexe f3dfd0e5e030829cc3fa6aec489df5b2bd4cd85bf5031aeb22b1cc1a3f968877n/a 
2018-11-09n/aexe 0b02fccc3315d646c2b2abc0de26a0fc778970af6f9113a32678de5485a74926n/a 
2018-11-09n/aexe 29f3f31c5806bcb5e1491b3ef74ab664e840ca312e0f92ee447bc569cfe98786n/a 
2018-10-11n/aexe 1df8de4735d01bdaa3d3ec0b3ded34b58d8455acf09d5bec2fe533188b011bbaVirustotal results 45.59%