URLhaus Database

You are currently viewing the URLhaus database entry for http://45.137.22.103/local/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1521336
URL: http://45.137.22.103/local/vbc.exe
URL Status:Offline
Host: 45.137.22.103
Date added:2021-08-10 07:29:04 UTC
Last online:2021-08-11 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-08-10 07:30:02 UTC to complain{at}rootlayer[dot]net)
Takedown time:1 day, 6 hours, 23 minutes Poor (down since 2021-08-11 13:53:14 UTC)
Tags:AgentTesla link exe opendir RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-11n/aexe da96032bc5f0e72470400b312d3ef844d313d3c5f254ecb80549331594b3ecebn/aAgentTesla
2021-08-11n/aexe af3f604cc73575f96881b058aa35f7437efffcefc6e97891ca4db615101159ean/aRedLineStealer
2021-08-10n/aexe 03d462a965108a9d9a216c4e26fa222c3fbba2e649a0e3e2cba8609070c6caf0Virustotal results 17.65%AgentTesla