URLhaus Database

You are currently viewing the URLhaus database entry for http://198.12.110.183/http/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1346817
URL: http://198.12.110.183/http/vbc.exe
URL Status:Offline
Host: 198.12.110.183
Date added:2021-06-09 16:55:08 UTC
Last online:2021-06-16 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-09 16:56:07 UTC to abuse{at}colocrossing[dot]com)
Takedown time:7 days, 4 hours, 20 minutes Bad (down since 2021-06-16 21:16:44 UTC)
Tags:exe ImminentRAT link LimeRAT opendir rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-16n/aexe d9afd09c966d09347356de994510d6718308384c76651eaa88f7252d8f579a7fn/a 
2021-06-14n/aexe 305514746c30fc10a9a4adbd87a6d7c63d55360442abcbc41933ec6efceb5fa3n/aLimeRAT
2021-06-13n/aexe 355b53fed23c55e1a184e85b1c108a09546bd20a2cc5e1e27350406edc0fbb86n/aLimeRAT
2021-06-11n/aexe f92a9df00bd6d01b6302e14d266fd1b6aa0df0e4f837e3b604eebb6daf631e03n/a 
2021-06-10n/aexe f2a489976001d04ddd83ba0cb2e49b0a523b6a6ccb25d0d8735f52796896be3cn/a ImminentRAT
2021-06-09n/aexe 4a9ceaeac471469be12c4c6b231b8597190192f4818e278c307a13533177f7f6Virustotal results 15.94%RemcosRAT