URLhaus Database

You are currently viewing the URLhaus database entry for http://198.23.145.147/400/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2207975
URL: http://198.23.145.147/400/vbc.exe
URL Status:Offline
Host: 198.23.145.147
Date added:2022-05-23 13:35:05 UTC
Last online:2022-05-30 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-05-23 13:36:06 UTC to abuse{at}colocrossing[dot]com)
Takedown time:6 days, 21 hours, 47 minutes Bad (down since 2022-05-30 11:24:05 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-29n/aexe 0ee9dbb864e490511ea698286f5da4996192d483678727ebc38f61f3d2d1d029n/aAgentTesla
2022-05-25n/aexe a840f64e25bfd288d2fec6bda879fdba0eeae14887f29bb0174fb4d84f7fb17bn/a AgentTesla
2022-05-24n/aexe e025b54582f0c0db9ae839534285a15381bc1428ff1ac21350b6881ace657f57n/aAgentTesla
2022-05-24n/aexe ba724f27172761e674892fe1ba78c3273e26bc8694e800dda14db5ef7cf86350n/aAgentTesla
2022-05-24n/aexe 5e06dde11fb80bd6712dd567fa95c3563e6dc467740a49bfba29749f84c946bdn/aAgentTesla
2022-05-23n/aexe 429fa5f097eb2e2ae64c67729f62ef129011521ff6a6618b3282ac0e6f8a29bfn/aAgentTesla