URLhaus Database

You are currently viewing the URLhaus database entry for http://carbinz.gq/modex/chungx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1219995
URL: http://carbinz.gq/modex/chungx.exe
URL Status:Offline
Host: carbinz.gq
Date added:2021-05-11 08:30:04 UTC
Last online:2021-06-09 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-05-11 08:31:02 UTC to abuse{at}serverion[dot]com)
Takedown time:29 days, 2 hours, 49 minutes Bad (down since 2021-06-09 11:20:45 UTC)
Tags:exe NetWire link rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-03n/aexe e49652ae364f8e79333c289887bd0c3e5dde9efcad680039863ad32ea8ac9724n/aRemcosRAT
2021-06-03n/aexe dbc2d79881e917ef4698fa6121191938e1e9614d6d1159de6df72908df3bb126n/aRemcosRAT
2021-06-01n/aexe b275490304d8b4ae0894b33319e3db7df9927986e2258ce3bc7f9b4037bc98b9n/aRemcosRAT
2021-05-25n/aexe 73bfb6718b6bf93f5c731a0b06b55c14645cf7c78628d8026966ec0e84b46cc3n/aNetWire
2021-05-25n/aexe 54c7d014bb356bd5593fa849e1648378bbeab338b70bfed0508723d23a6805b0n/aNetWire
2021-05-11n/aexe 4ae72c1d1198e6ff1e19bb210c61a10e847e703c1f77be90c76c7438a3de9be9Virustotal results 34.78%RemcosRAT