URLhaus Database

You are currently viewing the URLhaus database entry for https://conver.work/files/62_283cleaner.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1417371
URL: https://conver.work/files/62_283cleaner.exe
URL Status:Offline
Host: conver.work
Date added:2021-07-01 20:04:17 UTC
Last online:2021-07-16 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-01 20:05:03 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:14 days, 21 hours, 8 minutes Bad (down since 2021-07-16 17:13:11 UTC)
Tags:32 exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-14n/aexe d7cfab9ab1399aae36f468da34f3b2437e02183020c70b9b10dec2a67df6ed06n/a RemcosRAT
2021-07-14n/aexe b3c8e7adc498bf3560145c21917c9371d14532e70797306f713960abd9372f3an/a RemcosRAT
2021-07-09n/aexe a4697614a7348ff9eee3f604bf5bf201a9db702792f8227faa84feacc9472f9fn/a RemcosRAT
2021-07-09n/aexe 39c1cf05a4961c0e946d542b90e20a67a649e2142891e1b8072f825fe904644en/aRemcosRAT
2021-07-06n/aexe 1e8773bd333371c44ca0f157a8515d6ebc9db41e61ea20bc690c7d4e25d18bd4n/a 
2021-07-05n/aexe 41f469d18016a7ba9938f2f4409b7e15acd9657a4c639f772a05c53e93287aa7n/aRemcosRAT
2021-07-05n/aexe a34adec7742a2507e7e7337ab5e8b580460331fd5b687bdea8b322dcff7b538en/a RemcosRAT
2021-07-03n/aexe 3bb001d38dd85afd62000186b4d423fe41d3345598fb219f9ddf79521657df0fn/aRemcosRAT
2021-07-01n/aexe 704cea9cf2bcfaf5eb8e072ec299125703ff291d1223db387365079758e366bbVirustotal results 33.33%RemcosRAT