URLhaus Database

You are currently viewing the URLhaus database entry for https://myguyapp.com/c3.hta which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3390125
URL: https://myguyapp.com/c3.hta
URL Status:Offline
Host: myguyapp.com
Date added:2025-01-05 13:08:34 UTC
Last online:2025-09-24 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-09-22 15:40:15 UTC to abuse-network{at}squarespace[dot]com)
Takedown time:9 months, 13 days, 1 hours, 20 minutes Bad (down since 2025-10-15 22:03:23 UTC)
Tags:opendir RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-13c3.htahta 4e94fa887ac8f575cdd11c60d7700265a5ebcba0f731a45d1c989b09f0852297n/aRemcosRAT
2025-10-10c3.htahta 5662877c2be6c685ca2eea4fe9419df3fb838bba9afcf99516c676fbcd1eb302Virustotal results 0.00%
2025-10-10c3.htahta eb365505c9dc37482926369333f9f43f25c02e1575deddb4028862ca40581aafn/a
2025-10-09c3.htahta cb54c6edb1861db7fa3330252c051393a99f0406ed49aedfc62bc414ba499485n/aRemcosRAT
2025-10-07c3.htahta 643ce2b59537b5ed4e8786f4713dd3bf839c628934cc6765eefb026765e29ddbn/aRemcosRAT
2025-10-05c3.htahta 9e6800e000d6e4cfadd0ee4a184b17173a46c992733f9be13cfe5493c59c19bbVirustotal results 0.00%RemcosRAT
2025-10-02c3.htahta 4ab38f80b73f7b0d8a21434fb6ce8a4d8b1df12e489b752cb647b765de686734n/aRemcosRAT
2025-09-29c3.htahta 2c366abd6fb6bdd17dd234afff173565720aab31c5d1d7396ac0595b35be8cean/aRemcosRAT
2025-09-26c3.htahta c8638846eefddbcbd97d5cf879734e46abb6c12d6faffc411a0c061ed3a0eaffn/a
2025-09-26c3.htahta 1110443b9ea65c2145822c3cdd854224ae8c0419bd1bfb42bc38b9e5d185957dn/aRemcosRAT
2025-09-25c3.htahta c4feaeb8600b9957ea8c8688ec6bf63ab27fea2558a793ae77a4573beb9b7be8n/a
2025-09-25c3.htahta 68fcd82aa1f9c040a447fafc2a47f0ac3dac2a4b1cfb093803dca570137b580aVirustotal results 0.00%RemcosRAT
2025-09-22c3.htahta 344ac83b7290133f96cdabbec53c1dbf43b8148e82a840f79ac7aba00c86d2e4n/a
2025-01-16n/ahta cf0a8d7b9bba62cedb94b058693ef2c3afe4e41cd4c82f4fde9ec529e99834f8Virustotal results 20.00%RemcosRAT
2025-01-16n/ahta a70bc984039d77fc9e208f2daf97d2578032388ceee67fccf1da27d81d8ecfbaVirustotal results 36.07%RemcosRAT
2025-01-05n/ahta bbe818541c34a4def85455fa7a1392d2ded1e76ca6d89f08125a13d09ea4b93aVirustotal results 21.31%RemcosRAT