URLhaus Database

You are currently viewing the URLhaus database entry for https://45.200.148.45/dashboard/rem.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3309928
URL: https://45.200.148.45/dashboard/rem.exe
URL Status:Offline
Host: 45.200.148.45
Date added:2024-11-28 06:31:12 UTC
Last online:2025-01-06 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: lontze7
Abuse complaint sent (?): Yes (2024-11-28 06:32:19 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 9 days, 5 hours, 7 minutes Bad (down since 2025-01-06 11:40:15 UTC)
Tags:RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-03n/aexe fba22f1eed90be52c368f932cc1ab4d4b3683db3cba97c514d04d6acd0114ac6n/a RemcosRAT
2024-12-02n/aexe a1a334aa5fd2ba1b468b2fac316ffd7ffbf5708dfa85f966689fe43bc18602e3n/a RemcosRAT
2024-11-29n/aexe be001792d5c39ce7b9338da9671d06c9f462e998aca460a9d61f990906d0c001n/a RemcosRAT
2024-11-28n/aexe 517a86c20b4683b4ff139422c47ad976e5ae5c77a1cbdf84763a1bab346e0802n/a RemcosRAT
2024-11-28n/aexe 75bd47d5ceee272c90447619af57558ad85d9ed9cdd8d8e7d3da9520bdb4a3dbn/a 
2024-11-28n/aexe c0cda2df8bd8dd54aae2ed27c0fc78436eadba0dbbf96d05d6c905ffce33cd8bn/a RemcosRAT
2024-11-28n/aexe a63c26783dee7bb580a5cc5267a5b3e84ee9601b776d797175cfd70911135a76Virustotal results 65.71%RemcosRAT