URLhaus Database

You are currently viewing the URLhaus database entry for http://185.28.39.17:7777/185.28.39.18/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2709962
URL: http://185.28.39.17:7777/185.28.39.18/plugmanzx.exe
URL Status:Offline
Host: 185.28.39.17
Date added:2023-09-06 05:10:08 UTC
Last online:2023-10-28 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-09-06 05:11:05 UTC to abuse{at}des[dot]capital)
Takedown time:1 month, 22 days, 17 hours, 15 minutes Bad (down since 2023-10-28 22:26:50 UTC)
Tags:32 AgentTesla link exe NanoCore link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-16n/aexe dfb9b3c7cf15baa877da2d2c87e1e53761517094bab2de1a6b92ebca122fa858Virustotal results 28.57%NanoCore
2023-09-18n/aexe aeb8f27ac2bd40c4bb08aad29488af84d18b01a2be4b86cbe18dad6454d7c5e8n/a NanoCore
2023-09-15n/aexe 0955392ea6c671ce4420c13a7b169419722d3413acce7cad6d7377daf2b705fdVirustotal results 18.31% NanoCore
2023-09-08n/aexe 041ec16c93bb68d4da1b9827b9ee83b16745c79c7b3a886321400b57d89b9481Virustotal results 26.76% NanoCore
2023-09-07n/aexe 7c30f34150418dec870ac793198e613117da51eaa009dc45fe1ab0475adb1fc3n/a 
2023-09-07n/aexe 00f9a0e9d500d85a1a380a015b722b67947a10b7bc22ad583b60a249f82a74dbVirustotal results 26.76%AgentTesla
2023-09-07n/aexe 1fe2be77e4073e5575b553ba1183fcb619c73639031b19e95b20c9b894bacbd4n/aAgentTesla
2023-09-06n/aexe 3471210c4e4a41ee58c10df71d55b73bf3fa631f918654c55dda7b4d84e3bc51Virustotal results 26.76% RemcosRAT
2023-09-06n/aexe e6efc87407a88a82189a7fe864eff162fd8feb0d09fcb58f18655c758e7a0600Virustotal results 23.19%RemcosRAT