URLhaus Database

You are currently viewing the URLhaus database entry for http://176.119.30.28/pftp/Pecxhdsv.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:408796
URL: http://176.119.30.28/pftp/Pecxhdsv.exe
URL Status:Offline
Host: 176.119.30.28
Date added:2020-07-07 22:47:06 UTC
Last online:2020-07-08 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2020-07-07 22:48:02 UTC to abuse{at}v-sys[dot]org)
Takedown time:16 hours, 41 minutes Good (down since 2020-07-08 15:29:05 UTC)
Tags:AgentTesla link exe rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-08n/aexe 3cad10488e9efd31ba0fe6cacc311572a2fac4c4760b315e5ce337ea731ce22cn/aRemcosRAT
2020-07-08n/aexe 1887a3510750f3511193c6c51a64dd2af035402cafd8e8f4fc63666412ea010en/aRemcosRAT
2020-07-08n/aexe e67dd040ce53fbf4e0ef2121dabd060c5c764ede3eec55801376b144a0f40419n/aRemcosRAT
2020-07-07n/aexe 1aa2ba9a2898cc652c73b06bc862739c8a996f9f241b3c0dfd82115583b6e887n/aAgentTesla