URLhaus Database

You are currently viewing the URLhaus database entry for http://107.174.202.145/170/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2384196
URL: http://107.174.202.145/170/vbc.exe
URL Status:Offline
Host: 107.174.202.145
Date added:2022-10-25 10:57:06 UTC
Last online:2022-11-26 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-10-25 10:58:13 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 1 days, 19 hours, 17 minutes Bad (down since 2022-11-26 06:16:00 UTC)
Tags:AgentTesla link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-10-26n/aexe f8dd72e26f36b759975caec134a2ebe40acb84599226f4b880b631d572afcf43n/aFormbook
2022-10-26n/aexe c76592b7d6af661a15b6321308a27e054f49108b1a5b25d717636a241b384b93n/aAgentTesla
2022-10-26n/aexe a52d0bc31a250c5dd5c84c75fca9b965955297d20f582d79849c17fb59c4c04fn/aFormbook
2022-10-26n/aexe 98bd201c6a1ae16ccce5009af1cc3ec5b0dd46c31f1b814c93f91bc1376dc3cfn/aFormbook
2022-10-26n/aexe 817de551d33841a6a6d81e99b4ed25682e796857b694cec79daa45afdb5cede8n/aFormbook
2022-10-26n/aexe af29f1801cb7159de48605410405ecf431646f72d43f739b80822bdab747da9dVirustotal results 34.33%Formbook
2022-10-26n/aexe 335ae169f2389d9434a5b74ac0876d506dc1fe2ae4f8174be8a4ff06f409952bn/aFormbook
2022-10-26n/aexe f29d5743c803eef25515d7b5f61c1d8aa56a5e4c4a6c642299c614cd20de6164Virustotal results 25.35%AgentTesla
2022-10-25n/aexe 0f7b125f592ee7110788adfd925d51535c2196b0798a65263317e79cf30c3189Virustotal results 27.78%AgentTesla
2022-10-25n/aexe 6a4a22dbfbf1e4c43fcdc2f45da740e894d15c6f1bf39ccb8d9753e739e88004n/aAgentTesla