URLhaus Database

You are currently viewing the URLhaus database entry for http://mkontakt.az/en/a.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:194530
URL: http://mkontakt.az/en/a.exe
URL Status:Offline
Host: mkontakt.az
Date added:2019-05-11 07:02:17 UTC
Last online:2020-06-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2019-05-11 07:04:03 UTC to abuse{at}host1plus[dot]com)
Takedown time:1 year, 1 month, 15 days, 2 hours, 57 minutes Bad (down since 2020-06-19 10:01:59 UTC)
Tags:exe rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-06-16n/aexe 03e84f4a92771e5c87bec99f6027647ffaab9e14bc3ba31461a0292232d2b77cn/a 
2019-05-15n/aexe 9fb7622a493f2082d6c8e2dde5b9490c47acd78749af0749d6dcd5fff090077fn/a RemcosRAT
2019-05-15n/aexe dea615cc0d58d32a080f69fe4f9b9069fd6ed97e5ab9c2d7eb994cf989e4b4f6n/a RemcosRAT
2019-05-14n/aexe a1f9c8803a3d4137e7f7904daeb662f5d1594cdb92cb602fe9fa7f492f596a6bn/a RemcosRAT
2019-05-13n/aexe 38e7b5d077311660b7514f86939dcf26091460b88fd4e15650cf11b60494c395n/a 
2019-05-13n/aexe 09ae104f66181864c7fcf15fe66f3374b086b21e98d08846f4cbed729fe956a4n/a RemcosRAT
2019-05-13n/aexe 81ca48238755749c889889e0ee42757dbb93b5919c8c1f838b2965b79fdc8540n/a RemcosRAT
2019-05-12n/aexe aab241c819bb65c01427cf37f8194fcf4fccdade9c780a844bec3169fcb1c097n/a RemcosRAT
2019-05-12n/aexe 930d5794a8cc95999daf1c134509aeeb2ebc773147ed537b8835cc79338d38b6n/a RemcosRAT
2019-05-11n/aexe bf640250ee94521dc87b52a5abf82ea47c770abcc2ec1ab1821c4834321e339fVirustotal results 30.56% RemcosRAT