URLhaus Database

You are currently viewing the URLhaus database entry for http://sadiqgill.com/assets/fonts/New%20REMCOS%20TES.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:412467
URL: http://sadiqgill.com/assets/fonts/New%20REMCOS%20TES.exe
URL Status:Offline
Host: sadiqgill.com
Date added:2020-07-13 14:17:27 UTC
Last online:2020-07-17 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: cocaman
Abuse complaint sent (?): Yes (2020-07-13 14:18:02 UTC to abuse{at}dimenoc[dot]com)
Takedown time:4 days, 4 hours, 21 minutes Bad (down since 2020-07-17 18:39:24 UTC)
Tags:RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-16n/aexe 4096056536154e1fa5a10e3495cd3ddadf7c01022b7b65b0c35a67b2eac2bc6bn/aRemcosRAT
2020-07-14n/aexe d9d41cdde2431b6e492c7680ac77504d199eed8c49b69735450256effc125364n/a RemcosRAT
2020-07-13n/aexe c0abc3e4021f1a4d035fa9b9e7c788d8b74d4431c21e6ef094a925d8249976cfn/a RemcosRAT
2020-07-13n/aexe 082a4f6b33b0746c17d4a745ab7849bd7c9f9b2f887b2e86dac011fb3ec4e3b0n/a RemcosRAT
2020-07-13n/aexe 6274c01dd6783517a68267d2c6c2af38143ed35074cfc2372d8bc385a7c5f4e9n/aRemcosRAT
2020-07-13n/aexe c0b1ba178d886a9d71fb7ffd5b169bf023021e13c545e3cd8d15461221dd2006Virustotal results 50.68%RemcosRAT