URLhaus Database

You are currently viewing the URLhaus database entry for http://103.167.92.57/365cloud/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2055540
URL: http://103.167.92.57/365cloud/vbc.exe
URL Status:Offline
Host: 103.167.92.57
Date added:2022-02-23 12:56:34 UTC
Last online:2022-06-11 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-02-23 13:39:07 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:3 months, 18 days, 4 hours, 35 minutes Bad (down since 2022-06-11 18:14:42 UTC)
Tags:exe Formbook link opendir Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-05n/aexe 05ff01455d828c01fa195c19dd551f510fbda60382aa97f87a877d0128aa3308n/a Formbook
2022-06-03n/aexe a3deb1a6f947ce71a96a86502fe76a99944ab944b2fc4a6484210867688b9358n/a Formbook
2022-06-03n/aexe fcea0d5b7a3f6eea2d6335f544374ede01e332b6c266a3d82837a3b0c0a1184dn/a Formbook
2022-06-02n/aexe fdd16446b48303bb5970b6618e0a459198797d8169d465fd9e64f9871a7e1f26n/a Formbook
2022-04-06n/aexe 2da2fdf211a236802b620aa7827632c2454aded6c99b200fbd737c104c573bddn/aFormbook
2022-04-05n/aexe 4c3c6c154bcaba75d5871b2f4b39e101a33f85fa3b8c5cce162ad1fdb8c24f64n/aFormbook
2022-04-04n/aexe 736330aaa3a4683d3cc866153510763351a60062a236d22b12f4fe0f10853582Virustotal results 2.90%Quakbot
2022-02-24n/aexe 6a89b5f89e4b2f1abc1407e26b6b8dc7855d153a6c7eab878106f9fe93eb876bn/aFormbook
2022-02-23n/aexe 831f79faeff5bd6704c5aca840f3067b4762e5b6e6228b04221ccf351b146da7Virustotal results 24.59%Formbook
2022-02-23n/aexe 3db51e29aef16473b5febc21b1f3a8024c8da7c2b7f5600fbc5324713f5fd7c9n/a Formbook