URLhaus Database

You are currently viewing the URLhaus database entry for http://87.121.221.212/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2676888
URL: http://87.121.221.212/plugmanzx.exe
URL Status:Offline
Host: 87.121.221.212
Date added:2023-07-05 06:11:05 UTC
Last online:2023-07-26 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-07-05 06:12:06 UTC to abuse{at}des[dot]capital)
Takedown time:21 days, 1 hours, 22 minutes Bad (down since 2023-07-26 07:34:40 UTC)
Tags:exe NanoCore link rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-19n/aexe ffee4b5c77095f09469cf53177ab533e6bdbc9fd67b746e23af55094bdc7a8c5n/a NanoCore
2023-07-19n/aexe bab38eda4cf6d14186c7f751ceb34415348d9986552fe49b841fca8d083fa4cfn/a NanoCore
2023-07-19n/aexe c59e595eea586b663e06d17ada3674647bbac82dafa870e4407697668028c81bVirustotal results 21.13% NanoCore
2023-07-18n/aexe 780d049994ab5ffe68311633d44a7d807e4db84717d1c182bbda4edb5edc5531n/aNanoCore
2023-07-18n/aexe a2ccf50221d78c73a2015b13e340ee631d3c2bea60dbdfc74e1f5df8c920518eVirustotal results 22.86%NanoCore
2023-07-17n/aexe a8fcecf459448b45be84bfef1fa7d1ab4146716dd7591515438c15c979095eb3Virustotal results 22.54%NanoCore
2023-07-17n/aexe ce5f21e6926901d346279d3e0ec41bc1928afa188c554c733db0581a7e0ebb69n/aNanoCore
2023-07-13n/aexe bf373bfee0a0d9348814d70aa8cff3c8b7aedc7d21375203435e497eb9944ec3n/a RemcosRAT
2023-07-07n/aexe 2d2341a5b84b9ccce170815a654b91825cd05fa47f5d94d3e764680a5ac4095bn/a RemcosRAT
2023-07-06n/aexe ee6213dbb899250662c38091974bac9e7dfe549a969afaf5e79ece10ebaba2b8n/a RemcosRAT
2023-07-06n/aexe 9cff410693648c2750f557c04d4b2d3a0cabc3db9b4b666aa1ad6a4128e515ebn/a RemcosRAT
2023-07-05n/aexe 99ed6e63a6e0562da0a4accc3c868a50a04e5c4f7757c99808eddf6979b84587n/aRemcosRAT