URLhaus Database

You are currently viewing the URLhaus database entry for http://103.133.105.106/msoffice/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2247152
URL: http://103.133.105.106/msoffice/vbc.exe
URL Status:Offline
Host: 103.133.105.106
Date added:2022-06-22 06:54:06 UTC
Last online:2022-07-03 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-22 06:55:05 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:10 days, 19 hours, 21 minutes Bad (down since 2022-07-03 02:16:35 UTC)
Tags:AgentTesla link exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-23n/aexe 3f940b2f9acf9fc691e6e7cc6c6eecd64b3fc4f53ac1237899c8e0e51ea273fan/a AgentTesla
2022-06-23n/aexe c2aa6f1c088f58989849749905fd795eb7bf920d6482fcb49bf3a3a3d0d7c8can/aAgentTesla
2022-06-22n/aexe 1d0c844dd635dcdee374b276dd0d40b89dd000babecf14460f5857748474ff04n/aAgentTesla
2022-06-22n/aunknown 2b0701b29c7e1d11eca756136d829abf8da1ed98a281735c06d870c9dffbe7d3Virustotal results 0.00% 
2022-06-22n/aexe e595fa3aea9df94141690327bfa1c27d29b1e84df9cec782319ed4ecf8e394b3n/aAgentTesla
2022-06-22n/aexe eee6adbe2376d92010a17285408021e90ed1612c640ee069c4e633612236ad65n/aAgentTesla