URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.122.199/wmc/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1286604
URL: http://192.3.122.199/wmc/vbc.exe
URL Status:Offline
Host: 192.3.122.199
Date added:2021-05-26 12:44:04 UTC
Last online:2021-06-08 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-05-26 12:45:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:12 days, 16 hours, 27 minutes Bad (down since 2021-06-08 05:12:29 UTC)
Tags:AgentTesla link exe NanoCore link opendir rat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-05-31n/aexe 7043ac362acb68500619ebb06c569213dbe77aff3e381cffc99a308a79459c26n/aAgentTesla
2021-05-31n/aexe bcd373f753e42745f2eadf2db439b5c089853c50f9d3e50271fc9d9523b6bf54n/aAgentTesla
2021-05-31n/aexe b9c8cc02d2a7204ed77918b3ac05ec20cae7828560bafe6e8af9a7d84872d7a5n/aAgentTesla
2021-05-28n/aexe c6b6f77cbf5c49770a33a8d7198e4f81dd2a6b3584e76c90f8303269f6c69432n/aNanoCore
2021-05-26n/aexe 3d8811d64e17d5ea06d0edae6163b90b2400d06d9afa60ae689d6fe9232bca86Virustotal results 24.29%NanoCore
2021-05-26n/aexe 026468354a1bdf6893b8705e2f5d3a95065e4df8aa8b972888f8a8e319ebe1bbn/aNanoCore