URLhaus Database

You are currently viewing the URLhaus database entry for https://conver.work/files/195_101cleaner.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1417421
URL: https://conver.work/files/195_101cleaner.exe
URL Status:Offline
Host: conver.work
Date added:2021-07-01 20:20:08 UTC
Last online:2021-07-16 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-01 20:21:02 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:14 days, 20 hours, 44 minutes Bad (down since 2021-07-16 17:05:10 UTC)
Tags:32 exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-16n/aexe bf07b9144e804a0a1fb63f5f08ae9afc3f51d16fdc57be34812d39158e71df24n/a RemcosRAT
2021-07-13n/aexe 3a61fdcf898bb80ba0db54d11a5ca00cbf0867c52efc4ed249274b192a79b123n/a RemcosRAT
2021-07-09n/aexe b422bab6e44b0caeb6a2c779898c6ef9fea8efe1b5e9fd36fd3f07d6b57b0e2bn/a RemcosRAT
2021-07-05n/aexe f78b8f13eb0533a8ad4048ec71de54b8dd7d6f02add47d775fd96c3a557face6n/aRemcosRAT
2021-07-03n/aexe d048fbb3e93917050dd8e5f365ac32c31a969145ee4ada681d3d6f5427fed9dcn/a RemcosRAT
2021-07-01n/aexe 070dc47307cdec1dc80820401b39ecd316609f69815bfe7478ae16608a361fe9Virustotal results 37.68%RemcosRAT