URLhaus Database

You are currently viewing the URLhaus database entry for https://myguyapp.com/c1.hta which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3390124
URL: https://myguyapp.com/c1.hta
URL Status:Offline
Host: myguyapp.com
Date added:2025-01-05 13:08:06 UTC
Last online:2025-09-24 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-09-22 04:28:13 UTC to abuse-network{at}squarespace[dot]com)
Takedown time:9 months, 12 days, 14 hours, 43 minutes Bad (down since 2025-10-15 18:12:10 UTC)
Tags:opendir RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-15c1.htahta 7d9791d782389b41ff2d404af89bd0ca7d4fcd66aca90924ab0aa897f64a2315Virustotal results 4.84%RemcosRAT
2025-10-10c1.htahta 5662877c2be6c685ca2eea4fe9419df3fb838bba9afcf99516c676fbcd1eb302Virustotal results 0.00%
2025-10-07c1.htahta 9f7d9709800e86e7f7801fd1f0d1bf0aac4985fbcf19d79988cc3f7fcbdaaaaen/aRemcosRAT
2025-10-07c1.htahta 4fea28a88442b1f9c94676df4a781864a39a696ebaf8bd830b564422293ce897n/aRemcosRAT
2025-10-05c1.htahta 9e6800e000d6e4cfadd0ee4a184b17173a46c992733f9be13cfe5493c59c19bbn/aRemcosRAT
2025-10-02c1.htahta acfcbe23a50d1668ce1a528e6a7e0d41fff77d5e048345924bd1edb64363bb14n/aRemcosRAT
2025-10-02c1.htahta a49bcb458d806308ed425d9982c96a3563c05a6e8714fbdeb10eb8d968568993n/aRemcosRAT
2025-09-29c1.htahta 53d80d66ac0c4b75fc120dae7d801a1f204604cd6b0430f2beada542cbd21191n/aRemcosRAT
2025-09-27c1.htahta fb2d9e7dd1fde51d38ffe96ca143b341630449bb8166f76958692526de2648d5n/a
2025-09-26c1.htahta c8638846eefddbcbd97d5cf879734e46abb6c12d6faffc411a0c061ed3a0eaffVirustotal results 0.00%
2025-09-25c1.htahta 68fcd82aa1f9c040a447fafc2a47f0ac3dac2a4b1cfb093803dca570137b580an/aRemcosRAT
2025-09-22c1.htahta ded068de37f1d8d48d758963597b184d89badac5e469921e603234311c86afdcn/a
2025-09-22c1.htahta 12764e4909b2d35f94835f67f02bee352b37c924904fa0cc12eadaa3e70d910fVirustotal results 0.00%
2025-01-16n/ahta b7cd7840de7c9286335721dbd14ca25849599e290f2fcfcbcffd1daf678663ddn/aRemcosRAT
2025-01-12n/ahta a70bc984039d77fc9e208f2daf97d2578032388ceee67fccf1da27d81d8ecfban/aRemcosRAT
2025-01-06n/ahta bbe818541c34a4def85455fa7a1392d2ded1e76ca6d89f08125a13d09ea4b93aVirustotal results 21.31%RemcosRAT