URLhaus Database

You are currently viewing the URLhaus database entry for http://23.94.54.101/GVV.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2835512
URL: http://23.94.54.101/GVV.exe
URL Status:Offline
Host: 23.94.54.101
Date added:2024-05-02 13:20:12 UTC
Last online:2024-05-13 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2024-05-02 13:21:07 UTC to reportabuse{at}racknerd[dot]com)
Takedown time:11 days, 1 hours, 4 minutes Bad (down since 2024-05-13 14:25:31 UTC)
Tags:remcos link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-12n/aexe 79e89d3d34db960d4f1383741c154f9c2f630f57f810cb4e9a811d4fd984b9e2n/a RemcosRAT
2024-05-10n/aexe 6fc98a42ea485c9efa15ce99a9a896c3d39656ca8b22040da6893519c0eb6038n/a 
2024-05-09n/aexe c1e154a596dfe821140db4560c1014bbc4a580a209641fffb1c91c753a5397d1Virustotal results 21.21% 
2024-05-07n/aexe f74c9a27142f5d3b603ec72919a41255613c0a24ba0a34ffa3041a8e4a2a82aan/a RemcosRAT
2024-05-02n/aexe e28c8fc4052dbd472cc6245f605064f85ebb36371b43246066fdbeca547cbd17Virustotal results 30.56%RemcosRAT