URLhaus Database

You are currently viewing the URLhaus database entry for http://85.208.136.4/IHD.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2502222
URL: http://85.208.136.4/IHD.exe
URL Status:Offline
Host: 85.208.136.4
Date added:2023-01-09 14:47:04 UTC
Last online:2023-01-11 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-09 14:48:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:2 days, 8 hours, 17 minutes Poor (down since 2023-01-11 23:06:04 UTC)
Tags:exe rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-10n/aexe 12d40f09ff572ec60039c1a9b761f65b414c30831d5024f54e7a1098213a1b45Virustotal results 21.43%RemcosRAT
2023-01-09n/aexe e611419a4b0f0fb37a0c6ec8e6bd88c5314eb889f525ecf875eea8b6338a8f2cVirustotal results 39.44%RemcosRAT