URLhaus Database

You are currently viewing the URLhaus database entry for http://103.167.92.57/airdrop/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2163857
URL: http://103.167.92.57/airdrop/vbc.exe
URL Status:Offline
Host: 103.167.92.57
Date added:2022-04-25 16:01:06 UTC
Last online:2022-05-08 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-04-25 16:02:10 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:12 days, 23 hours, 7 minutes Bad (down since 2022-05-08 15:09:44 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-27n/aexe 8ba3166fa29eedff427b62c2d1b05984949a1ac87a34ffa2ab95f4404e96d0e7n/aFormbook
2022-04-26n/aexe eaa4358b74f5002a614bb2ef19d311ff270ff912b3ce4329bbd0ee0fb26bd71cn/a Formbook
2022-04-26n/aexe d1f7d4ab84422973af4c1f787ebf10a88089e364a7ed637f6a861d5e09849024n/a Formbook
2022-04-25n/aexe 8e50b1dcbaf8524aeb9c18eb365692a2913fcc269f257f6272e511c682d93188Virustotal results 40.30%Formbook