URLhaus Database

You are currently viewing the URLhaus database entry for http://84.54.50.31/D/Dollar.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2650476
URL: http://84.54.50.31/D/Dollar.exe
URL Status:Offline
Host: 84.54.50.31
Date added:2023-06-02 16:12:05 UTC
Last online:2023-08-26 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-06-02 16:13:05 UTC to abuse{at}delis[dot]one,abuse{at}des[dot]capital)
Takedown time:2 months, 24 days, 12 hours, 11 minutes Bad (down since 2023-08-26 04:24:58 UTC)
Tags:64 exe RemcosRAT link zgRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-19n/aexe e1cf35a98cc9a3e08243dce9b26b0aa4468cdfa06b4a3f7615f7e088e195bdc4Virustotal results 25.35%RemcosRAT
2023-06-16n/aexe 0f611b87697a816d5b37f745fa94c89315327ba3458c190fe41efd891ccd5196Virustotal results 22.86%RemcosRAT
2023-06-02n/aexe 5460fc226b1d4fe8e3d5c11e4afcd3b4ee67ccc9725ac71d27d6e1a5ea36f1d2Virustotal results 35.21%zgRAT