URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.220.22/430/dllhost.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3201691
URL: http://192.3.220.22/430/dllhost.exe
URL Status:Offline
Host: 192.3.220.22
Date added:2024-09-30 08:24:10 UTC
Last online:2024-10-09 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-09-30 08:25:12 UTC to abuse{at}colocrossing[dot]com,net-abuse-global{at}hostpapa[dot]com)
Takedown time:8 days, 21 hours, 32 minutes Bad (down since 2024-10-09 05:57:42 UTC)
Tags:exe GuLoader link Neshta rat RemcosRAT link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-08n/aexe b808bce615791843332f609a17e3fa795abe30ea7500264093af1bf07e16f4b2n/a Neshta
2024-10-08n/aexe 55e35b8a87aae2422fdafbbacd3c8c410e8b8586dbdd8f1d0ed793d187a6ddb8n/a 
2024-10-08n/aexe 9936616e401f84aa41f9d27c34d6ac7754f1b58a82b7c92cc3d70fe5e65a3816n/a 
2024-10-07n/aexe 178ebc7a9fb6e2a0b5c0da522572f14ff56fa50e60507d552940256dbe596645n/aSnakeKeylogger
2024-10-07n/aexe b47db283e7d8e91c9a0c520dc0734155e9d2bf033811461c14f3e81242909db6n/a SnakeKeylogger
2024-10-02n/aexe 4e11fd9ebcd710646c1c685691837f3e2d4983e9232279ece12a6db9be569ba1Virustotal results 22.54%RemcosRAT
2024-09-30n/aexe 9124d7696d2b94e7959933c3f7a8f68e61a5ce29cd5934a4d0379c2193b126beVirustotal results 22.22%RemcosRAT