URLhaus Database

You are currently viewing the URLhaus database entry for http://198.50.242.157/FXServer.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3401362
URL: http://198.50.242.157/FXServer.exe
URL Status:flame Online (spreading malware for 1 year, 4 month, 17 days, 14 hours, 11 minutes)
Host: 198.50.242.157
Date added:2025-01-15 08:07:07 UTC
Threat:Malware download Malware download
Reporter: lontze7
Abuse complaint sent (?): Yes (2025-01-15 08:07:36 UTC to abuse{at}ovh[dot]net)
Tags:exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-07FXServer.exeexe f9cee948c1b89c90c68dbdd853dae5d414a6b479f6324506ffa77b2cb4a4c11cn/a RemcosRAT
2025-01-20n/aexe 32d8c2a1bb4d5a515d9eb36c1286b0ac08624c8ea3df0e97f12391558ce81153Virustotal results 88.89%RemcosRAT
2025-01-17n/aexe 3b4341374f5db8e0892cfb0e4991a003c1aee88dccfe68bd8b987552b8d594ebn/a 
2025-01-15n/aexe c80871c2c51b513894b20774fc1da5c7c0b46fb57d5085ef08eb2ebd02c11deaVirustotal results 18.31%RemcosRAT