URLhaus Database

You are currently viewing the URLhaus database entry for http://augustair.com/Resources/eft/edi.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1523982
URL: http://augustair.com/Resources/eft/edi.exe
URL Status:Offline
Host: augustair.com
Date added:2021-08-11 05:38:07 UTC
Last online:2021-09-24 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: AndreGironda
Abuse complaint sent (?): Yes (2021-08-11 05:39:14 UTC to abuse{at}uk2group[dot]com)
Takedown time:1 month, 14 days, 3 hours, 8 minutes Bad (down since 2021-09-24 08:47:25 UTC)
Tags:bitrat link RedLineStealer link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-23n/aexe 19f7f97c17580f22d17edc3e01639286a09eb587863dd298aebee46125bf5307n/aRemcosRAT
2021-09-14n/aexe 3eff13340e0b34b34a87485ef702924b8b80fa506f120c297c8474c3afcc2c85n/aBitRAT
2021-09-13n/aexe f193f6876576b6969474c670850280a89df1091b0abfea162d74b98483c7314dn/a RedLineStealer
2021-08-24n/aexe 54d90bf7f12a3b1369e8ef4f708a58fed9d7950e1a87c9d5d805b974a148ce9en/aBitRAT
2021-08-17n/aexe 29dd2b13f081a0c7f8312c4b4c433ccdcc3b3a83b91a16a88393370dda44f60bn/aBitRAT
2021-08-16n/aexe 71c81318d16023aba7c537168d68b7d87eeeb085725d0904c3ea7298fc43d7e8n/aBitRAT
2021-08-12n/aexe 9d077371cd1d6dc2b8b337d0bc978afb1e910a947bb0e14c15a37c70c745704cn/aBitRAT
2021-08-11n/aexe bf6b69cb7063d748e6404300ed8b587473b20b2239605862ccbec909bccf7485Virustotal results 29.41%BitRAT
2021-08-11n/aexe 6d7fac5d7bfe833eb0756a174ceb9ea8280cd3f9858215924284af1b559bd81fVirustotal results 18.75%BitRAT