URLhaus Database

You are currently viewing the URLhaus database entry for http://85.202.169.21/ikmerozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2248578
URL: http://85.202.169.21/ikmerozx.exe
URL Status:Offline
Host: 85.202.169.21
Date added:2022-06-23 18:10:05 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-23 18:11:04 UTC to abuse{at}serverion[dot]com)
Takedown time:22 days, 23 hours, 2 minutes Bad (down since 2022-07-16 17:13:55 UTC)
Tags:32 AveMariaRAT link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-14n/aexe 5010aaedb07994095876efc390a8afd73cc32bc31a7fbfb60d676b92727270c5n/aAveMariaRAT
2022-07-11n/aexe 67c57cea9dc0c15a36684709d07e3d25e8c94e895b8193c8ebf6c86ec24e6371n/aAveMariaRAT
2022-07-07n/aexe 2048959922ad23073452866b19f570be842b928b5f3b6046162feaceb4d6cc49n/aAveMariaRAT
2022-06-27n/aexe 260937a104d6f0d58fd4e7b526af0290477216f0cdd1e6d38ccf55f33ca007e4n/aAveMariaRAT
2022-06-27n/aexe a953155598de30994a74ba28bc46f3bfef60e40583407f563106d82120af2df7n/aAveMariaRAT
2022-06-23n/aexe a5b2c3d108598dba61a7e972af4d9eb3f465a0e6f3b0c66cf779275f3268a313Virustotal results 49.25%AveMariaRAT