URLhaus Database

You are currently viewing the URLhaus database entry for http://195.3.146.180/server.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:928402
URL: http://195.3.146.180/server.exe
URL Status:Offline
Host: 195.3.146.180
Date added:2020-12-18 15:54:04 UTC
Last online:2020-12-28 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-18 15:56:02 UTC to rndata[dot]abuse{at}altnet[dot]lv)
Takedown time:9 days, 9 hours, 49 minutes Bad (down since 2020-12-28 01:45:56 UTC)
Tags:exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-19n/aexe ecee44992b84f86f98c14b5af66451c9e6306e7db33d038cef6d7292988da559n/aRemcosRAT
2020-12-18n/aexe f2e511e33e03f9c419e40c6f91770efa23ed9472017d7c2af1266690673260edVirustotal results 68.57%RemcosRAT