URLhaus Database

You are currently viewing the URLhaus database entry for https://bitbucket.org/downloadrepe/downloadrepe12/downloads/remco.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3297745
URL: https://bitbucket.org/downloadrepe/downloadrepe12/downloads/remco.txt
URL Status:Offline
Host: bitbucket.org
Date added:2024-11-21 00:05:11 UTC
Last online:2024-11-25 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2024-11-21 00:06:11 UTC to abuse{at}amazonaws[dot]com)
Takedown time:15 days, 19 hours, 34 minutes Bad (down since 2024-12-06 19:40:55 UTC)
Tags:base64 bitbucket Encoded exe RemcosRAT link rev-base64-loader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-02remco.txttxt 46333e83fd715fcd29456f316941f504021238a7f0f8ba4a89827b03f83d6aban/a RemcosRAT
2024-11-25remco.txttxt bbcbf1fb4c5fb0223fe676ac7a21c34a2edc448b45a4a989f86b416d1dcecdefn/a RemcosRAT
2024-11-21remco.txttxt ac10953a908ae794c5ee180add9124a78c69705135688e502bb56ce4453da749Virustotal results 27.42% RemcosRAT