URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.141.146/ppt/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1407071
URL: http://192.3.141.146/ppt/vbc.exe
URL Status:Offline
Host: 192.3.141.146
Date added:2021-06-28 11:33:04 UTC
Last online:2021-06-30 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-06-28 11:34:02 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 day, 19 hours, 30 minutes Poor (down since 2021-06-30 07:04:48 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-29n/aexe babb13711f57e5b2379adadccf787f0e20255866f21605191e1f518eeb8fc8a9n/aAgentTesla
2021-06-28n/aexe 62fae970bb22dd732021e862e08743be6b365e1aaf95b9ac49351c5930686749n/aAgentTesla
2021-06-28n/aexe e62d94d18fecf24b0de7f8298685b35e6afecfeeddcc8ec73f038b6c2eddf2e0n/aAgentTesla
2021-06-28n/aexe 69d6ba4ed00ec8b1990fd34b31f2b7abba0e3b711e85a9f0bc11276325d5ddb4Virustotal results 35.71%AgentTesla