URLhaus Database

You are currently viewing the URLhaus database entry for http://79.110.49.21/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2673230
URL: http://79.110.49.21/plugmanzx.exe
URL Status:Offline
Host: 79.110.49.21
Date added:2023-06-28 03:55:06 UTC
Last online:2023-07-17 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-06-28 03:56:06 UTC to abuse{at}sukhoi-su-57[dot]com)
Takedown time:19 days, 19 hours, 0 minutes Bad (down since 2023-07-17 22:56:32 UTC)
Tags:32 exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-30n/aexe df906c77d802e4e977ff24b11e1840d6948338250023a27b2b30ad9ac6e3f4ban/aRemcosRAT
2023-06-29n/aexe 49e4d4f6aaf967b656487d0d3dc27ecf3812b2d454b85339ae9ea79021bbe0d6n/aRemcosRAT
2023-06-29n/aexe f60667b9e2a0a25221cdb47844149beb3b1cd08abbc3360e8684fad9d8aaa20en/aRemcosRAT
2023-06-28n/aexe 34bfed7f2450542d851b696685ed0a43438683a54f1756a947119d7258a4adb1n/aRemcosRAT
2023-06-28n/aexe a8ae7002d16df08878c864f8cd2f8722dfcb5950372f3b12c88f4e265f2eee40Virustotal results 30.00%RemcosRAT
2023-06-28n/aexe 5e95168687b15de3724b3c8240c0b40cdb61c75b440d11a7fa72c2b247c920aeVirustotal results 56.34%RemcosRAT