URLhaus Database

You are currently viewing the URLhaus database entry for http://194.180.48.59/blessedzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2664675
URL: http://194.180.48.59/blessedzx.exe
URL Status:Offline
Host: 194.180.48.59
Date added:2023-06-17 10:05:06 UTC
Last online:2023-06-24 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-17 10:06:05 UTC to abuse{at}des[dot]capital,abuse{at}serverion[dot]com)
Takedown time:7 days, 0 hours, 7 minutes Bad (down since 2023-06-24 10:13:49 UTC)
Tags:exe rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-22n/aexe dc091920175bd059d2925977e1806df9930c40db5292a73158bac390fca03d75n/aRemcosRAT
2023-06-21n/aexe 95685a995f2645b0014492450917081410f3f244a9c19841b96ded0c80becf62Virustotal results 27.14% RemcosRAT
2023-06-21n/aexe 950bd7f2c479f24c6828dc41137161a8ec13828547bcbf8e0767cb28bb48640aVirustotal results 30.00% RemcosRAT
2023-06-20n/aexe 5081ac93d0c2369f432c5a4a74e9bca2978c9b05f23234d2c6b858d3da0f23a0Virustotal results 21.13% RemcosRAT
2023-06-19n/aexe 61dd5ffe6eae5f4bfa7299b37a7c0dea469d76b698200126cafc14a45acc1ba2Virustotal results 25.71%RemcosRAT
2023-06-19n/aexe 69d8898866b06b49cba9f6c4ac0832b0a1cec9a307e4c1af0e7a389ccd6d2288Virustotal results 28.17% RemcosRAT
2023-06-18n/aexe 657f37fb30624df1ecf67596efb6e279d9333addac2d006e8ab8c4fccc29915fVirustotal results 21.13% RemcosRAT
2023-06-17n/aexe 9271b609db698f886795f121d1d110acf0a4959eaf5d94a93ade96b6a6cf0a95Virustotal results 36.62%RemcosRAT