URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.228.85/svch/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1170319
URL: http://192.227.228.85/svch/vbc.exe
URL Status:Offline
Host: 192.227.228.85
Date added:2021-04-26 08:38:05 UTC
Last online:2021-04-29 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-04-26 08:39:04 UTC to abuse{at}colocrossing[dot]com)
Takedown time:3 days, 8 hours, 45 minutes Bad (down since 2021-04-29 17:24:53 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-04-28n/aexe 0a23b7f6c2790165d41ce79ee23cb01c8d1f0c2716775a9bc614e35ca1b11a53n/a AgentTesla
2021-04-27n/aexe b032521341d2f76b1fe69ead761ce67c48fd4ebc7c4ecdb4e7d81dc8b9935e1en/aAgentTesla
2021-04-27n/aexe 3f2f7e69a97b02fd0bbb40580b8f419f24da6276db9993dd33ec2653a633f5can/aAgentTesla
2021-04-27n/aexe c7f4ad3987c2026cd2051b487f34e9f2a56249dc319ab066497be27e01a2ea6en/aAgentTesla
2021-04-26n/aexe 4f855be83abc988837527da6ec58df5be3e4b1415f3337f42e9686e56a32286bn/aAgentTesla
2021-04-26n/aexe 1cc623e73d0c6eeedfb75a89406c71dd183847f290133b73e470d20068384700n/aAgentTesla
2021-04-26n/aexe be2f04a275b8e5ed96a9edadda30f16a5b3661824a339a00ed5119e7b0d95998n/aAgentTesla
2021-04-26n/aexe 9a7cc833405fabd1375ba99a3d19d8ec53243fe3f06b01ba01b2c58c519105dfVirustotal results 17.39%AgentTesla