URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.18/abokiii55%205.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3559203
URL: http://213.209.150.18/abokiii55%205.exe
URL Status:Offline
Host: 213.209.150.18
Date added:2025-06-07 21:26:09 UTC
Last online:2025-09-15 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-06-07 21:27:18 UTC to abuse{at}virtualine[dot]org)
Takedown time:3 months, 9 days, 18 hours, 35 minutes Bad (down since 2025-09-15 16:02:58 UTC)
Tags:exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-09abokiii55%205.exeexe c5dec2cc1a3b67e4fb4e7c829c40b614a3c08d4179383e15e68c1777ff7977f4n/a RemcosRAT
2025-06-09abokiii55%205.exeexe 471c82524c262fee5a27206396ea224678a80891dbf0bc71cf9f919c6ec04056n/a RemcosRAT
2025-06-07abokiii55%205.exeexe fecc4abfa69131e47d5630b5f784b06cb3e84303aaf493f3d29037fa2483b266Virustotal results 32.39% RemcosRAT