URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.95.135/S0704M/wininit.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2805139
URL: http://192.3.95.135/S0704M/wininit.exe
URL Status:Offline
Host: 192.3.95.135
Date added:2024-04-08 14:17:11 UTC
Last online:2024-04-15 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2024-04-08 14:18:05 UTC to support{at}vpsace[dot]com)
Takedown time:7 days, 6 hours, 42 minutes Bad (down since 2024-04-15 21:00:36 UTC)
Tags:remcos link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-04-09n/aexe 0d1277800ce70608ae6223a3361f709c7c68743178ca51fe3a2409a610c76de5Virustotal results 25.35% RemcosRAT
2024-04-08n/aexe 3610a513abb50127c22a6c5d2c84b814a5743ba2de685c031725601a23f3bdc3Virustotal results 23.94%RemcosRAT