URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2641293
URL: http://194.180.48.59/plugmanzx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-05-26 05:46:05 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-05-26 05:47:06 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:29 days, 4 hours, 21 minutes Bad (down since 2023-06-24 10:09:01 UTC)
Tags:exe NanoCore link rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-15n/aexe 38106a2209026f52e0be443c19aa6f520ced381b00ce20ab78d547475cc24872n/aRemcosRAT
2023-06-14n/aexe 9e6406269fe3e1f7a309e3ee01e4770d6f5c7abd2dead9afc7eddfedcdb04295n/aRemcosRAT
2023-06-14n/aexe ca19795538ded5ca26ae167d5417cc200d51ff7738e36695fbb05b305dbc15b6n/aRemcosRAT
2023-06-12n/aexe 8e861cbf43bd4068930cb5ef3821cab163fad49d42b77c66b70fff8fa038db48n/aRemcosRAT
2023-06-12n/aexe df3fecfed5c29b48b262fe85865b29ec15b4eb494baf7a38ce5a1a7609368130n/a RemcosRAT
2023-06-09n/aexe 18cd3063dcc655b5b9bffc3692d2e2fbc7199ee08e9c6ab01a1d7a6d6b9cc10en/aRemcosRAT
2023-06-09n/aexe 6d7415fdd99aa5fe2a3ab117680ca84aa851c27a7e4ccb831583d1df5b06f465n/a 
2023-06-05n/aexe ac7983522d429ba0141b567f6e7606e4c8f11065f976f306c4222a2110d8a2daVirustotal results 22.54% RemcosRAT
2023-06-05n/aexe dd9cd5c5c5beff466b7e6f56a235bb27f76131489f6123bab49ef5339f433eeaVirustotal results 30.99% RemcosRAT
2023-05-30n/aexe 70d856cfc4e27c7ca18c939fd13fb989a308c64c0cd78d5d6f07759cc355c3dbn/aNanoCore
2023-05-30n/aexe 77dd08fac6833c6ef555e84c2ef5599ed10b7e6dad2da324e4ad643e843709d0n/aNanoCore
2023-05-30n/aexe 4188fbef59670a8fa8cee6a75514de835973823c58e66f6d5b622c695bd1ad07n/aNanoCore
2023-05-30n/aexe 5b1e8d8e1c47866009a79f371befaff9f673cb07656a0eb9509771dffd8f7ea7n/a RemcosRAT
2023-05-29n/aexe d935d16b1603eb83d9c8587e3fe36ba247341adb572bac99a291f35bd13d7292n/a RemcosRAT
2023-05-29n/aexe c57ef56c3465d7d32b6851cdfd6d950fbbc53a40c825f547f4b4cc0f01123346n/a RemcosRAT
2023-05-27n/aexe 541a0946336f8cfd222ce29f9aa665b823c985622907c89019dc7dd9682541a5Virustotal results 39.44% RemcosRAT
2023-05-26n/aexe 43c39e05ae59835e16df8bd732cd035292db70bc2c2d6d95ac354622bfa376ecVirustotal results 24.29%RemcosRAT