URLhaus Database

You are currently viewing the URLhaus database entry for http://mantis.co.ug/rc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422764
URL: http://mantis.co.ug/rc.exe
URL Status:Offline
Host: mantis.co.ug
Date added:2020-07-31 10:27:35 UTC
Last online:2020-08-16 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-07-31 10:28:04 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:16 days, 4 hours, 0 minutes Bad (down since 2020-08-16 14:28:45 UTC)
Tags:exe ModiLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13n/aexe 624a70f95caa8cd4fa87ba48fd1b351fe5232ca62f09ceca6f5663b6cd0de71dn/a ModiLoader
2020-08-11n/aexe 36f02b0b6fe558dde6dc31b1eec25e40f6de8a7fc2f43f633dfac3976773bb46Virustotal results 26.09% ModiLoader
2020-08-09n/aexe 7b91e75a75b9f3e2b8d28114cedfdbc8488f06781e55ba87a8418e46d19c5a14n/a ModiLoader
2020-08-07n/aexe d6a94c89eb79fb49c744e26cca9501380947c212b3d68f034315789c22dfb5ben/a 
2020-08-06n/aexe 9bed429738732f0c9603490e676d6cd141c64e368d1546118d98ef4caa4275fdn/a 
2020-08-04n/aexe 6916d0f41d35a9142e598496a1e996616b4fad6d15f0f3da7ec9210b6a124586n/aModiLoader
2020-08-03n/aexe e57919cacc4eaf696b8f35c98e9581eaa557bf50c788444d511ae91e94129909n/a 
2020-08-02n/aexe ef926123bc1ea19504727130349bee2451eac7e51b8032cc91e11f2fbae8caedn/a ModiLoader
2020-07-31n/aexe 08fe7e61eafc062a5f50981fae0f578442cdfd31a00e2398389c8bea37485f02Virustotal results 16.95%ModiLoader