URLhaus Database

You are currently viewing the URLhaus database entry for http://84.54.50.31/D/H2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2650472
URL: http://84.54.50.31/D/H2.exe
URL Status:Offline
Host: 84.54.50.31
Date added:2023-06-02 16:04:04 UTC
Last online:2023-08-26 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-06-02 16:05:09 UTC to abuse{at}delis[dot]one,abuse{at}des[dot]capital)
Takedown time:2 months, 24 days, 12 hours, 13 minutes Bad (down since 2023-08-26 04:18:46 UTC)
Tags:64 exe RemcosRAT link zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-07n/aexe e69d1e9f023deebccd2174f8507017de6ce4d62fb2c3603b708be5889c371b22Virustotal results 30.99%RemcosRAT
2023-06-06n/aexe 80ea9f71426b05efb585d8d8807321a5aa8f652be7cf79e91c518cbda0b424fcVirustotal results 30.99%RemcosRAT
2023-06-05n/aexe 6ca06d119da53e4bcd4752e62971541d0d4d2cfc86bad01b9ba8253c3d2615d3Virustotal results 36.62% zgRAT
2023-06-02n/aexe 617c26fdcee79a9c0bf97456acaa65c691e7269866ad88aabf655330d2fc50bdVirustotal results 23.21%RemcosRAT