URLhaus Database

You are currently viewing the URLhaus database entry for http://192.227.158.116/bulinco/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1692693
URL: http://192.227.158.116/bulinco/vbc.exe
URL Status:Offline
Host: 192.227.158.116
Date added:2021-10-18 18:20:05 UTC
Last online:2021-10-25 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-10-18 18:21:03 UTC to abuse{at}colocrossing[dot]com)
Takedown time:6 days, 20 hours, 52 minutes Bad (down since 2021-10-25 15:13:10 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-20n/aexe 354a944ec435b9735f3ca37b7d594b3acbf8077b6cbacb520a0f9b5f8dbc42a3n/a AgentTesla
2021-10-20n/aexe b4554d82dba5e6e904df40846f0c0914c25ac0bcba24c38cab310a066a38072bn/a 
2021-10-19n/aexe 816c0f7e9fe03057d6ad0cbb7e93b97e3e5da9c508421b1e7ac6db3fd32e0ae7n/aAgentTesla
2021-10-18n/aexe 20e9c3ad420ffd76094590adced58f056d38e5d6afe3ee9e21e7b29ff5a80da7n/aAgentTesla