URLhaus Database

You are currently viewing the URLhaus database entry for http://103.145.254.163/hhttsm_h1/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1847971
URL: http://103.145.254.163/hhttsm_h1/vbc.exe
URL Status:Offline
Host: 103.145.254.163
Date added:2021-12-03 10:26:06 UTC
Last online:2021-12-05 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-12-05 16:49:57 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:4 days, 4 hours, 4 minutes Bad (down since 2021-12-07 14:32:28 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-06n/aexe ad33f1b47b2ac6b1ec5eea318baf1bfe8f9bb2f6d02fd1667da7aeeb351205e2n/aFormbook
2021-12-05n/aexe 13d4188437fd7caf662393052ef82808bf70cdb5e31fcc2f162ad2dffad377aan/aFormbook
2021-12-03n/aexe 29e7d7eec0c8b07eac1b67b2875c1942104495e5e37f8b08fd788d4157376b1bn/aFormbook
2021-12-03n/aexe da78d337e87a2b0ed5447b7d9d5dabb42968690ff3e16d68aa6131cbc2327a2fVirustotal results 24.24% 
2021-12-03n/aexe 83f6ae731d42e5b754955cc68e0289a7b30592e04121cbea6f51a90845c331ddn/aFormbook