URLhaus Database

You are currently viewing the URLhaus database entry for http://pub03832.duckdns.org/cymt/done.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:587553
URL: http://pub03832.duckdns.org/cymt/done.exe
URL Status:Offline
Host: pub03832.duckdns.org
Date added:2020-09-21 16:29:37 UTC
Last online:2021-01-14 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-09-21 16:30:04 UTC to abuse{at}bladeservers[dot]eu)
Takedown time:3 months, 24 days, 15 hours, 55 minutes Bad (down since 2021-01-14 08:25:27 UTC)
Tags:exe QuasarRAT link RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-14n/aexe d525ff0349a9ce04dc5f0016540611080c996d5fba67a2935015e7c1dac58166n/aRemcosRAT
2021-01-12n/aexe d246f2f9a393a321c7a39217968f742126522994bc68b56018f25937b6b1039an/aRemcosRAT
2020-12-29n/aexe 86992692d34557946a1fd9a96b11789d1ba43b74eb41eeb99181c53ec8c0840cn/aRemcosRAT
2020-12-27n/aexe 3bdfd4cd7aacdefa4ab159a25b056056fd011b9ad60fc2166adbb41c5610b044n/aQuasarRAT
2020-12-26n/aexe 1230b290a583361b44a14b0ebf16925f07d7d6ed0d58ecae0bdd2419903d27b0n/aQuasarRAT
2020-12-26n/aexe 47d53feeaa5e7f8f8d8af8aba5b86a805e3276a35d3b785e4fd3275c54c52809n/aQuasarRAT
2020-12-24n/aexe 40b5d0462edaa8a9f567a3c5080e954a6d1897d6375ca4bd55017aedaf8f583fn/aQuasarRAT
2020-12-03n/aexe 32f481a7c5c4c551ff62fed04373d59417592eec20592bfd748d894d5f04de02n/aRemcosRAT
2020-11-28n/aexe c3c9aff6dc79b5e5b273e0df686f7896cae920de3ffd171cecdede3a1402725cn/aRemcosRAT
2020-11-19n/aexe 9cd872a2f048755fda7442e506d886474842523bab26b2fa90c4473505d49a61n/aRemcosRAT
2020-11-19n/aexe 2304ca5f716360f0b184ab6f4b0daa63862c3418d69bb4d1706a8506cd3bda4en/aRemcosRAT
2020-11-18n/aexe 44814687b7a037b5d9083e7f678408f1499013d11e765d3881da8dbecbce81c1n/aRemcosRAT
2020-11-17n/aexe 21b63e2e1226fdacd86d2662b14d9e750d98655a06504e151be154391670c859n/aRemcosRAT
2020-11-16n/aexe dd848661f56da431f26eeb2d6c05b08e6e6051357f2ad6a4e36e1a55ee3c1f36n/aRemcosRAT
2020-11-14n/aexe 3745a056d8f798d0b84a3b1cbaf5858f38f1f7cc3198d66a95e65c18302fba03n/aRemcosRAT
2020-11-08n/aexe 4b65b0ef6e5df94c275433e72f1fd9e3c549b313210c6542cbd319e5399fbd26n/aRemcosRAT
2020-11-08n/aexe 2fff352ace60c16a4f7402f015a777e7fd383d6b4759f147b6a126b390d9ff52n/aRemcosRAT
2020-11-08n/aexe a9e9036ea6ac587bcaab8c8b4a5537a092b54dd4daeed3254df7bb4af6926c90n/aRemcosRAT
2020-11-07n/aexe 60cb0cb27fa975e50e9a2b2b5538a0b1b30070171b775ed531297b0b76268905n/aRemcosRAT
2020-11-07n/aexe 5cbcddc6136a4692ec6065f531645033a8ee69aaff25f5a0033fffab705c01a5n/aRemcosRAT
2020-11-05n/aexe 6d5f672d7f0f898fcbd61de854ebb606307557eccfd30b5e0cd76f689da29234n/aRemcosRAT
2020-11-05n/aexe c583fe59628fa5aa1146213fd49234db4509dc5cc451861c9b3a314b52d9a3e7n/aRemcosRAT
2020-11-01n/aexe 023945848fc191b504323fbfbe71288affa36bde374d9d4889d083fd27341723n/aRemcosRAT
2020-10-31n/aexe 596802440276cf7c17a24c0f108f21647579ca06d6bd1299bea1b82d5121afa1n/aRemcosRAT
2020-10-31n/aexe a351faaa23105c8fde3cada56019c460dd7bc8579e027dfb56ef630e0b8649c5n/aRemcosRAT
2020-10-29n/aexe 958139fdff65190d5ec118b4ac6ceec3a2d4b69932e72edb4ce6ae308ba13f47n/aRemcosRAT
2020-10-23n/aexe 61feaac6ffb4031baff62a70bf36a38e69e849685c1e3edfe0ddbbfe220abd7an/aRemcosRAT
2020-10-21n/aexe 95167e64d46e5f0e9821b379aa7e412f57d14fe11e613bdcab38cb47dc217bbcn/aRemcosRAT
2020-10-18n/aexe 04794ec7e7eb5c6611aada660fb1716a91e01503fb4703c7d2f2099c089c9017n/aRemcosRAT
2020-10-18n/aexe 5a418e084b49b740a94d307baf45d67ac25db462fdeb80065fb60ffeb197273fn/aRemcosRAT
2020-10-17n/aexe 523bf7a1e425337861ae402b035f000fcf7a06d270a81ab638ca74445aa60bfan/a RemcosRAT
2020-10-17n/aexe e037b5ebac7b3ac81b3e268268dbd072784c73f178662e4a66e5e57d7e8a67c3n/aRemcosRAT
2020-10-16n/aexe 3270cfe3f15d8303d43e64e082d89eabb0737af61637393ed6d4922c3cba3909n/aRemcosRAT
2020-10-16n/aexe b4b5110b2babce8946d262e6f75215f1c7a6f036eeb3eda5223b9430d5235d46n/aRemcosRAT
2020-10-14n/aexe 4a024542511c7d0a40e8317486b7177eaf71ee355f1731f17bc632731ea814b0n/aRemcosRAT
2020-10-13n/aexe 6637c089017af9c448d8235e20db32603d8547f0611187341cf184dc66c170b4n/aRemcosRAT
2020-10-13n/aexe 257b2b1a5694438c684e9d4fd44141fc3f09a18d15ebef5e46aad1603afa0b0cn/aRemcosRAT
2020-10-09n/aexe 2aca994114835d2663353454df341285535994068284d9cbbb03e2e87f388b80n/aRemcosRAT
2020-09-29n/aexe e0b880ceabc161ebb31168c2dea4e4c37f90d710411a630eddc5b5340fd87ea8n/a RemcosRAT
2020-09-21n/aexe c7f0d624874b4f37b5926b13bdb804981bf48800f07eb161ef027d68f50b6afbVirustotal results 41.18% RemcosRAT