URLhaus Database

You are currently viewing the URLhaus database entry for http://visam.info/update_vbase/VOKLIGHTD.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:1364597
URL: http://visam.info/update_vbase/VOKLIGHTD.exe
URL Status:flame Online (spreading malware for 5 years, 0 months, 8 days, 4 hours, 39 minutes)
Host: visam.info
Date added:2021-06-14 09:36:05 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-08 06:41:40 UTC to abuse{at}oneandone[dot]net)
Tags:32 exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-25VOKLIGHTD.exeexe 9fbe0e1e4667293e6596298570486db49f3017d99a5bc2f40ad20d691b5c4e62n/a 
2025-08-09VOKLIGHTD.exeexe 4cc37c909f34c7b5f65b314a46c145918b3661d593e24a0a37efcc789edbb692n/a
2025-04-28VOKLIGHTD.exeexe 49437b63f90f4003928e16a98cb1f2674e6ee791c4df6a20c3592e31f9f4227dn/a 
2022-03-30n/aexe 31c74a2da791dfd66395248e4157784ee10a7dcb4b7201089ec7ef4fa3f49ea1n/a 
2022-03-14n/aexe 8bddde9f82ab5ec6f759a57d117a69a6a090c77a89ca2d30d34b52e947d971b7n/a
2021-09-29n/aexe a573f854718450992761756c51fe22e1c91781100c2685b754ebc2a8491f4b6an/a 
2021-06-14n/aexe e2e80df13f72ce8833c2b41643da4a1f99eb5af25422a40d1250a8a40cc92c2cVirustotal results 18.84%