URLhaus Database

You are currently viewing the URLhaus database entry for http://s-rco.duckdns.org/11d/solex.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1557705
URL: http://s-rco.duckdns.org/11d/solex.exe
URL Status:Offline
Host: s-rco.duckdns.org
Date added:2021-08-23 16:10:05 UTC
Last online:2021-08-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-08-23 16:11:02 UTC to noc{at}vdinetwork[dot]com)
Takedown time:6 days, 23 hours, 19 minutes Bad (down since 2021-08-30 15:30:51 UTC)
Tags:exe GuLoader link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-30n/aexe 617738e1dd2b1ca260fe4cd650b249406c2b26adf903f38e8bf7b6b6cae031e2n/aRemcosRAT
2021-08-30n/aexe d90a7f2445955fbd15e28dfe8a66702a80a6458d5f082217d18033d77bfd30e3n/aGuLoader
2021-08-25n/aexe 66b556164347eed63a310fdcb78f59c29a3be82b8527f2e0d8d412ae68a1078an/a RemcosRAT
2021-08-25n/aexe 576c45faf084a4f7d282e460ee207cd9a6dc269444701ee211f9aeb7879efc35n/aRemcosRAT
2021-08-24n/aexe 70921226f4c6dd8d21672150cc0115b107c395f848aa89975ed3bb42c7eccd69n/aRemcosRAT
2021-08-23n/aexe 860e16c192167d5dd823b8e533858cdada7aa9b3173254f2f57031af68b84e0cVirustotal results 23.53%RemcosRAT