URLhaus Database

You are currently viewing the URLhaus database entry for http://23.95.13.176/rim/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1649282
URL: http://23.95.13.176/rim/vbc.exe
URL Status:Offline
Host: 23.95.13.176
Date added:2021-09-30 15:28:05 UTC
Last online:2021-10-04 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-09-30 15:29:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:3 days, 16 hours, 30 minutes Bad (down since 2021-10-04 08:00:00 UTC)
Tags:exe Formbook link opendir RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-02n/aexe a955e327adfdbd6478598d32fbe89d3517fa5fa5bf9a46e1bd9ab960f3bcc2a4Virustotal results 36.76% RedLineStealer
2021-09-30n/aexe 99a52f15cbd0ceb13b15070bbbab2eee59974d15e8d4aaed562b015d888294c5Virustotal results 16.18%Formbook
2021-09-30n/aexe 9cbd20f7dfa4e57fa2adcf34f86c5e2a04b36e346493995d6c9ef85c3960eeb7n/aFormbook
2021-09-30n/aexe 2cf9a6fd4361184dbe79b2067472bdb6ac2907b89e78e213cf0eadd69ed10cd1n/aFormbook