URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.212.137/swiss/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1507223
URL: http://198.23.212.137/swiss/vbc.exe
URL Status:Offline
Host: 198.23.212.137
Date added:2021-08-05 07:46:05 UTC
Last online:2021-09-05 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-05 07:47:02 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 1 days, 7 hours, 24 minutes Bad (down since 2021-09-05 15:11:28 UTC)
Tags:32 exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-01n/aexe 533fd8da75df1b1ba32eb92e70fcc930920a8839736e50c043c5df11eed21dd2n/aLoki
2021-09-01n/aexe f2d2638afb528c7476c9ee8e83ddb20e686b0b05f53f2f966fd9eb962427f8aaVirustotal results 0.00%
2021-08-06n/aexe c2a568e116a85d6085f78797c6906be3986236bdebc72c8e50638798aed60503n/aLoki
2021-08-05n/aexe d586560a58ad44be9be80b819685a714d228d98596f1b44c4b08bdebc1c108dbVirustotal results 26.47%Loki