URLhaus Database

You are currently viewing the URLhaus database entry for http://77.223.119.85/rxm.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3508758
URL: http://77.223.119.85/rxm.exe
URL Status:Offline
Host: 77.223.119.85
Date added:2025-04-12 16:18:05 UTC
Last online:2025-04-17 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_WT
Abuse complaint sent (?): Yes (2025-04-12 16:19:12 UTC to abuse{at}selectel[dot]ru)
Takedown time:4 days, 20 hours, 27 minutes Bad (down since 2025-04-17 12:46:22 UTC)
Tags:booking ClickFix dcrat FakeCaptcha

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-16rxm.exeexe 514c249747f46c377b6fc1944c09e0029f9f0697111269b32ab4b1e0f680d271n/a DCRat
2025-04-15rxm.exeexe 84d4ea5ba407799d8ff8c10bf12efe5635db80bd7a9c79f9ee3056da3726262cn/a 
2025-04-14rxm.exeexe 12f2bb9b775ebabd48b2020f5916da3b2259600cb6649e053154fa036ccf7b94n/a DCRat
2025-04-13rxm.exeexe 55317d9604919c7e878c0965de7020e850bfb406a2a2959dc2d4546aef05335fn/a DCRat
2025-04-12rxm.exeexe a4846d7540225062d89a5bb08fdc3ed947e0ca684507a5f21bfe7d71bbcc2dd3n/aDCRat