URLhaus Database

You are currently viewing the URLhaus database entry for http://41.216.183.128/47/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2359955
URL: http://41.216.183.128/47/vbc.exe
URL Status:Offline
Host: 41.216.183.128
Date added:2022-10-11 10:02:05 UTC
Last online:2022-11-11 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-11 10:03:09 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 0 days, 14 hours, 36 minutes Bad (down since 2022-11-11 00:39:24 UTC)
Tags:exe QuasarRAT link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-17n/aexe 9e619346d77fe346c8fa4d351e2f0366867c51353d074bd268496306dff704bcn/aSnakeKeylogger
2022-10-14n/aexe 9c9edf8d303e0b1bd10a4c0abe4f2cc02f873f1d2aaadd851d5273b27e3d9c14n/aSnakeKeylogger
2022-10-13n/aexe d96ada3f41c4faedb35e88ba807897d141fc04a6f53a255de03ec3df3060c448Virustotal results 28.17%SnakeKeylogger
2022-10-12n/aexe ddbc8012d2d452db94873a384b977cf40fd991abb9826487e8fc5ed94c72328fn/aSnakeKeylogger
2022-10-12n/aexe be60fe1356a96d21cb257e80f85cd5b48ab376b827809f1fe63b23a7eddabca7n/aSnakeKeylogger
2022-10-11n/aexe 5e58c0004cf6475000ee34ee6d551955e4dc6b9e48ad8323b59aeee44d785a1dVirustotal results 58.57%QuasarRAT
2022-10-11n/aexe d40f32f81438c0c6bad28f8b8b08ebb452871640a691cb879ea1a4220b452017n/aSnakeKeylogger