URLhaus Database

You are currently viewing the URLhaus database entry for http://109.206.241.93/ede/ede.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2271619
URL: http://109.206.241.93/ede/ede.exe
URL Status:Offline
Host: 109.206.241.93
Date added:2022-08-11 08:53:03 UTC
Last online:2022-09-09 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-08-11 08:54:05 UTC to abuse{at}neterra[dot]net)
Takedown time:29 days, 14 hours, 29 minutes Bad (down since 2022-09-09 23:23:55 UTC)
Tags:exe opendir RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-09-07n/aexe 5c7c518d4d1c35115e72d2985e12669cfe526afe09704df0112ec6d9538cf6ddn/a 
2022-08-15n/aexe 8b2e62c33657add18454ba8a2e0a2701dff0bbbf8a12b7c66d3c5c22e3c5c07dVirustotal results 24.29%RemcosRAT
2022-08-12n/aexe 40948ea3149f6561dffc9599179b142e6d5ff5ec97af45c9e8a5ba35671eba1en/aRemcosRAT
2022-08-12n/aexe 1e894aeb21c7599eeace1408865c683439f4ff3d2114e0e8007a3423cdd386b4n/aRemcosRAT
2022-08-11n/aexe dfed5249564b04f77e9dae3e45c13cb520635e345cf5c0976967062e5054e54dn/aRemcosRAT
2022-08-11n/aexe fbe8fa4ed7f1de962147afcf13e21f3f5e96b329fa6369f12a05641857828c27n/aRemcosRAT
2022-08-11n/aexe fe6a93368c9da83d864b3f37fba5c8c01302a3d909779cb3bd6dfaed8b430fb5n/aRemcosRAT
2022-08-11n/aexe 9ca00f3a2728b3aa3405877af0408777ebf3f5ee7db17ea8ba87d1fd4da0d39dVirustotal results 22.06% RemcosRAT
2022-08-11n/aexe 436cf5e6015bb698449e308b6cb6071e4404eeb29bb830ad28cd1442740f5c29Virustotal results 21.13%RemcosRAT