URLhaus Database

You are currently viewing the URLhaus database entry for http://medicalcorp.ro/royal2/helper/gd/zt/jbrowserQ.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:869725
URL: http://medicalcorp.ro/royal2/helper/gd/zt/jbrowserQ.exe
URL Status:Offline
Host: medicalcorp.ro
Date added:2020-11-30 13:11:12 UTC
Last online:2020-12-04 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2020-11-30 13:12:03 UTC to abuse{at}mxhost[dot]ro)
Takedown time:3 days, 18 hours, 57 minutes Bad (down since 2020-12-04 08:09:45 UTC)
Tags:QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-03n/aexe d3b2b32d51ae45785f5292b9f2b8d131e15d886bd47d2c6a62eb65cf8c38d206n/a 
2020-12-01n/aexe 7f3e5e8e94217110c158eb909a519c8878da9b887267e028454948d4b9a52ca6n/a QuasarRAT
2020-12-01n/aexe 23ed6ef7aec39fbc37b613e5ad3611a84ba1facc92489ed818dcc72bee129022n/aQuasarRAT
2020-11-30n/aexe b3e1f3ed2ed33bd4d98232515b01f134dc62f5b2a440d8ed9abb9a163b2afcadn/a QuasarRAT