URLhaus Database

You are currently viewing the URLhaus database entry for http://192.210.175.102/test/putty.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2645524
URL: http://192.210.175.102/test/putty.exe
URL Status:Offline
Host: 192.210.175.102
Date added:2023-05-30 10:25:08 UTC
Last online:2023-08-03 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-05-30 10:26:04 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 months, 4 days, 19 hours, 12 minutes Bad (down since 2023-08-03 05:38:24 UTC)
Tags:exe Formbook link GuLoader link opendir RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-01n/aexe 7247a3f88c9926488072d10907f19c9ed6b73f2ad2e218c89749d53957ba0362n/aRemcosRAT
2023-07-27n/aexe 8af777d0f92cef2d9040a634527c3753669235589c23129f09855ad0ebe10c6fVirustotal results 1.43%
2023-06-22n/aexe 0d771bed67134df3cfcbafe953d9378ca9a40ba93f05f726b9286638a08318e4Virustotal results 21.13%RemcosRAT
2023-06-15n/aexe 9eff7acd854aca75b8d69c9bf9768d24d4485b470ab6e64c70cfba412b05140dn/a GuLoader
2023-06-14n/aexe b12104293019ae6a6def352c2da72dd57ebc8cb76d64ebe8fd10e43b62db0554n/a 
2023-06-13n/aexe f5d770ad14eb5b2837c828e26ea941b2ef469bbed61e4aef0e62f5f46bbeb7e2n/a 
2023-06-12n/aexe d268693524fc895727d54f8aa8e74b98477528850b911fc65ef156127dff161an/aGuLoader
2023-06-07n/aexe 7401712b8abb2ea748bebf808879e8219c1ec21d3bb75a88725945b8098c727eVirustotal results 5.63% GuLoader
2023-06-07n/aexe 0bead9471e37db2824ecfc53366757e940926a1d7c04af7da6e799465ad1abc7Virustotal results 6.15% 
2023-06-07n/aexe b69766d0e0291d9e2999bdacef4d317aa548afa8f7608e98265784a9ec924533Virustotal results 4.29% GuLoader
2023-06-06n/aexe 4460d790ec6c72ee2c6025a561ffb8189f41fee0682fad825cbd96d9b081efdcVirustotal results 5.63% 
2023-06-06n/aexe 4ad6c38be212777a181c374f391ebecdaed23e1a6449219005228c8a4f3a7ca8Virustotal results 12.68%Formbook
2023-05-30n/aexe f2d2638afb528c7476c9ee8e83ddb20e686b0b05f53f2f966fd9eb962427f8aaVirustotal results 0.00%