URLhaus Database

You are currently viewing the URLhaus database entry for http://augustair.com/log/remit/edi.jpg which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:832150
URL: http://augustair.com/log/remit/edi.jpg
URL Status:Offline
Host: augustair.com
Date added:2020-11-19 08:02:05 UTC
Last online:2021-05-10 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-01-27 04:08:04 UTC to abuse{at}uk2group[dot]com)
Takedown time:3 months, 13 days, 19 hours, 50 minutes Bad (down since 2021-05-10 23:58:43 UTC)
Tags:Encoded RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-04n/atxt 27b32d0375a6aff4ae330d9a574dfcc17d14f37b6adea3727d337388585b2483n/a 
2021-03-17n/atxt 49be31aeff0dd112d067ce1eb1b8d3b2f5cc9ad0d9ed903ed0565fb51a4bd23bn/a 
2021-02-25n/atxt 7d0a476538855ebcd55313366a753d89566c40712d5c522575f424ef61c3d81fn/a 
2021-02-17n/atxt 0287c3b3799b18a86c95d279802562dcfc493a5b9fed6938c8b9c4a9224fcd29n/a 
2021-02-10n/atxt 81a73957e44bfadbef17d234c592b261dbe9a5c828ad8c99547cc82547914018n/a 
2021-02-04n/atxt 47909d7b5ccde1376d77acc283653ec760000ec9041a5ad1997d05c94586ea2an/a 
2021-01-29n/atxt 1e3219f6a22bcd8194eefbac02f05c063aedf77196b25d52461dd81d878bf2c2n/a 
2021-01-27n/atxt f34aba4ec6ef12489570885c37d16336d39babb89d476bbe86a331890916cb74n/a