URLhaus Database

You are currently viewing the URLhaus database entry for http://taurus.ug/rc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:998435
URL: http://taurus.ug/rc.exe
URL Status:Offline
Host: taurus.ug
Date added:2021-02-10 07:40:06 UTC
Last online:2021-07-04 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-02-10 07:42:03 UTC to automatic-abuse{at}eliteteam[dot]to)
Takedown time:4 months, 24 days, 14 hours, 14 minutes Bad (down since 2021-07-04 21:56:53 UTC)
Tags:exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-30n/aexe 4be9060105bafe3c28b9cbca8208a69952c4c524cb45398e0443e29ce2323e1cn/aRemcosRAT
2021-06-30n/aexe fd25d0297a8890cb63206e28835e6441adb8bb2b7b72b0e85afe5270a4796446Virustotal results 84.06%RemcosRAT
2021-02-18n/aexe f0e41d9b327900eb04d7f027b5ebcbff42d19e654abc6b0db114792ff2538e77n/aRemcosRAT
2021-02-16n/aexe 9945152f2509b0f8bccc5813830e6584502ceab5e5cc73912ef1b3950fee0cb9Virustotal results 34.29%RemcosRAT
2021-02-10n/aexe ae382c0784bb8b15bfd36fc7664819f06be96ef8b34ab399f7a76f672a2ea445Virustotal results 56.34%RemcosRAT