URLhaus Database

You are currently viewing the URLhaus database entry for http://2.59.254.18/_errorpages/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2696805
URL: http://2.59.254.18/_errorpages/plugmanzx.exe
URL Status:Offline
Host: 2.59.254.18
Date added:2023-08-03 05:51:05 UTC
Last online:2023-08-23 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-08-03 05:52:05 UTC to abuse{at}icxhosting[dot]com)
Takedown time:20 days, 4 hours, 15 minutes Bad (down since 2023-08-23 10:07:39 UTC)
Tags:32 exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-11n/aexe 26cae4cdeef032aea2bd4ea1c5b88fbfb876bb3dd35a54076356195969fe3611Virustotal results 33.80% RemcosRAT
2023-08-09n/aexe 0fe9312c5237b767dc07de6296a5a7aaf8b7c7ec4540f1c65f158aba5079a283n/aRemcosRAT
2023-08-09n/aexe 8aae048958f1eb9e76e5b01174d4055763e4af720d0b48c4e2741ee7da3bc222Virustotal results 32.39%RemcosRAT
2023-08-08n/aexe dfe0f95ffc9ad74d75e0c2089a34fd96594e47b9c635eb5c884cec8f1d20ef0an/a RemcosRAT
2023-08-07n/aexe ff450b9ba2302dbefa84542c8818a0c233b303c126c2c01aee019c7fbf6340b8Virustotal results 38.03%RemcosRAT
2023-08-07n/aexe 920fae943bbfb6cb7dd1a1a13e6abfb6f951ed79eaa01b9b693ff6a8224ae1e1n/aRemcosRAT
2023-08-04n/aexe 75e57d3f76491b9bc7fe155b20ea8f9498892bd54a34824fca50bf0ae4a1902en/aRemcosRAT
2023-08-03n/aexe 22181c3078de3df406f094899b2032b946d1472a40d3d0349757d9c759d29ce4n/a
2023-08-03n/aexe abe74320624508bf03e3a0c1024fbff5b4109751931182856d8e18ad784f010an/a RemcosRAT
2023-08-03n/aexe c14657190bec0bf6b8fd9ef47563657948aa3ea66a43e7d0224c7662f323e144Virustotal results 23.94%RemcosRAT