URLhaus Database

You are currently viewing the URLhaus database entry for http://103.153.78.204/dhl_invoice_2337990/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2261599
URL: http://103.153.78.204/dhl_invoice_2337990/vbc.exe
URL Status:Offline
Host: 103.153.78.204
Date added:2022-07-26 15:35:09 UTC
Last online:2022-07-31 11:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-07-26 15:36:05 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:4 days, 20 hours, 7 minutes Bad (down since 2022-07-31 11:43:39 UTC)
Tags:AveMariaRAT link exe ModiLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-27n/aexe ec599414aa02c36f5ce655f53cfbe39fb835929afcef6d8bcab79fa92a6de236n/a AveMariaRAT
2022-07-26n/aexe fe2fffb702293dbc48720067ba92f6dcb45982b05a25b5f11f2c6ecdd6cd55c4Virustotal results 14.29% ModiLoader
2022-07-26n/aexe e670e7e426009d13b122f0f1bcc48c4f3cfcaaa3dd6159704290435c23200190n/aAveMariaRAT