URLhaus Database

You are currently viewing the URLhaus database entry for http://107.172.75.154/600/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2084653
URL: http://107.172.75.154/600/vbc.exe
URL Status:Offline
Host: 107.172.75.154
Date added:2022-03-08 17:45:06 UTC
Last online:2022-03-23 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-03-08 17:46:08 UTC to abuse{at}colocrossing[dot]com)
Takedown time:14 days, 15 hours, 36 minutes Bad (down since 2022-03-23 09:22:50 UTC)
Tags:AgentTesla link exe Loki link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-23n/aexe 84272caf71507cce479a9a13b9bdf781d381ceff3efc1fdf17bd68cb136c2966n/aLoki
2022-03-10n/aexe 3de169fe99589d51aacc722eba5615fe2ec579f880e6c3cd8fdd329df4226273n/a AgentTesla
2022-03-09n/aexe 954d7cd522bd82b72db7e3767e2bf13b2bddcf384daea1739d3bbf9545c739cbn/aAgentTesla
2022-03-09n/aexe efbb010d372c4cd9daf73de6bb352c646c2daf8b159d3ce5885f3a802551e5b2n/aAgentTesla
2022-03-09n/aexe 17fdc0ff982ff2d426b2285b3c7acfb82944cb39f3431fd278082ab05251cd8cn/aAgentTesla
2022-03-08n/aexe 71aa8901c68763b5ca7724471187feeec18600a496d66abc93ab2b95ff35034aVirustotal results 30.43% AgentTesla