URLhaus Database

You are currently viewing the URLhaus database entry for http://198.12.127.217/global/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1599382
URL: http://198.12.127.217/global/vbc.exe
URL Status:Offline
Host: 198.12.127.217
Date added:2021-09-07 10:47:09 UTC
Last online:2021-09-12 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-07 10:48:04 UTC to abuse{at}colocrossing[dot]com)
Takedown time:5 days, 8 hours, 19 minutes Bad (down since 2021-09-12 19:07:12 UTC)
Tags:32 exe Formbook link Neshta RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-09n/aexe 9c8f32833d3c63f139b6ac0c3c7cbfcfbdd0f6a67c78b35bfe44bd8476d6e8b8Virustotal results 88.41%Neshta
2021-09-08n/aexe 6df73577c25cc76f19b536e44f6e4ad5e65b98599c8ff95f31dab97c3d0b0514n/a RedLineStealer
2021-09-07n/aexe c8754a0701ed69c237eb6e69f2dd6e026ab385a949940506d64fb4872c1f308fVirustotal results 35.29%Formbook