URLhaus Database

You are currently viewing the URLhaus database entry for http://136.144.41.109/GWI.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2059382
URL: http://136.144.41.109/GWI.exe
URL Status:Offline
Host: 136.144.41.109
Date added:2022-02-25 06:02:05 UTC
Last online:2022-03-15 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-02-25 06:03:07 UTC to abuse{at}serverion[dot]com)
Takedown time:18 days, 15 hours, 47 minutes Bad (down since 2022-03-15 21:50:21 UTC)
Tags:exe GuLoader link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-05n/aexe 72bb4a68f56282391552f33e3f32415ca046081b1823049778a6522f2d5f0e43n/aRemcosRAT
2022-02-28n/aexe 878e201d99e71462a088223e1a116e4921a2a40335c7895b4353eca70321246aVirustotal results 32.86%RemcosRAT
2022-02-27n/aexe 6a138e42906dc51f713b723737ee06e9dcdd885c9aa5f3d7abe237e1628e990fn/aRemcosRAT
2022-02-25n/aexe 96a2d30749242d463fd712a06f16d57114da115c37421a3d34bed73e089b08f1n/aRemcosRAT
2022-02-25n/aexe 99f100122f5280ac44bc01f3bb7df9d3bd69681335e5f50d4ddfeca6e8ac3cb1Virustotal results 10.14%RemcosRAT