URLhaus Database

You are currently viewing the URLhaus database entry for https://subirfact.com/desktopditor.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2711658
URL: https://subirfact.com/desktopditor.exe
URL Status:Offline
Host: subirfact.com
Date added:2023-09-14 08:07:33 UTC
Last online:2023-09-14 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: vxvault
Abuse complaint sent (?): Yes (2023-09-14 18:04:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 18 days, 5 hours, 43 minutes Bad (down since 2023-11-01 14:24:45 UTC)
Tags:exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-24n/aexe eb24859e40c12c57bd8f0febc01a75ecde6b5e15b5322dd29d657e2b2a5dfb20n/a 
2023-09-26n/aexe 4c09176981ccb4d6f7c48c6c88d4aad6ec13d5ad9b8afe41cdb40c749933f6b0Virustotal results 8.33%RemcosRAT
2023-09-25n/aexe d9bd0fb6a1868d4ea19dfadf3db1b7c1d12e4fe5b171d700e0d77066a26cd7dbn/a 
2023-09-21n/aexe 7e3760827a46bbc44108b5e6a7ea07418b7fc6fb64a58bab240759e9907a52f6n/a 
2023-09-21n/aexe b86f66d63bba75a764089277857f7c413bccb8df5f17d1a29ef27e4b0568e36an/a 
2023-09-14n/aexe bdd8f37906415bcb5b8b541376358b07517afea5cefd379b279f75155a4cdb1an/aRemcosRAT
2023-09-14n/aexe a64134838fe31566beaf7e4bcfe55f868d6eb2d0f05c06c82fc126e140c7e684Virustotal results 7.04%