URLhaus Database

You are currently viewing the URLhaus database entry for http://levitts.ug/rc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:414727
URL: http://levitts.ug/rc.exe
URL Status:Offline
Host: levitts.ug
Date added:2020-07-18 07:49:21 UTC
Last online:2020-07-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-07-18 07:50:03 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:12 days, 7 hours, 12 minutes Bad (down since 2020-07-30 15:02:49 UTC)
Tags:exe ModiLoader link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-28n/aexe 8fa8051d68f0b059927318bc2b712fa94f7a2426e0ad00061e3c3dc2206bf955n/aModiLoader
2020-07-23n/aexe d40ed1285acb1e8e2e8186291feffdc8a716837218e81ba27d4f3ce2485ad73fn/a RemcosRAT
2020-07-22n/aexe d54b0e29ca93d99346fd3c79409bd0ff599a8487603ac61c9cc14d34e74502d2n/a ModiLoader
2020-07-21n/aexe f158368c489837c721cb01f7bf86f18536f9948f35f2ced67827d638b8253f16n/aRemcosRAT
2020-07-20n/aexe b3dfbf42ff4e7958e10cc913ce51f6e30e90993d666224bfd404762e0e3b0386n/a 
2020-07-19n/aexe 2e1b3dec1609efaee181ea5c2865ace9ac7be4b5ee8420a71ef9fff500440377n/aRemcosRAT
2020-07-18n/aexe f3453d83f263aa7665cb7398e7216db55cb8d7d75b8d45cdaf889c9265ba72fbn/aRemcosRAT