URLhaus Database

You are currently viewing the URLhaus database entry for http://198.12.110.183/win/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1336838
URL: http://198.12.110.183/win/vbc.exe
URL Status:Offline
Host: 198.12.110.183
Date added:2021-06-07 15:18:04 UTC
Last online:2021-06-24 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-07 15:19:02 UTC to abuse{at}colocrossing[dot]com)
Takedown time:17 days, 0 hours, 21 minutes Bad (down since 2021-06-24 15:40:08 UTC)
Tags:exe ImminentRAT link LimeRAT njRAT link opendir OzoneRAT link rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-22n/aexe defe5a24ac909cc14b06b49ea8574ee1bc964569bf1d18d56d3dd4398daffcdeVirustotal results 58.57%OzoneRAT
2021-06-22n/aexe 922df0c7eaf792e0dd260b52fce268625dc77a0fe6f867cdc0e74281c8f40eecn/a 
2021-06-22n/aexe b4f0d107e95fa6f3aaae96d0341f0f0ad90b2dfa1fe7d9e04903eb2354a39dedn/aLimeRAT
2021-06-22n/aexe 4ae8e9234ed9ad9bd18825e4ec51a08af7a2d46028cc33ab922d1b509636f512n/anjrat
2021-06-22n/aexe 1c84bce4090447991d4190b6b90c8c5bc862fc8354e9f9000c77d0e05c087165n/anjrat
2021-06-21n/aexe 902ff53f079547c5b9f39af553fc3db0303445213baae544313f11f2768f73bbVirustotal results 30.00%njrat
2021-06-11n/aexe 0770f6a18c202cfd5ce412c498074521975d258ad2526f0b5d6182b724a0eaf6n/a 
2021-06-08n/aexe 3cb853c5a68e83cf022fe677f37b5b25a6e8a890f2c137d553fad61ef8b0bce6n/aRemcosRAT
2021-06-07n/aexe 975cc3f3bd2bc6b0c3ba35733f0a3aee2b7772ab0410be735bf6f708cd379820n/aImminentRAT