URLhaus Database

You are currently viewing the URLhaus database entry for http://52.29.58.98/100/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2422388
URL: http://52.29.58.98/100/vbc.exe
URL Status:Offline
Host: 52.29.58.98
Date added:2022-11-17 08:46:06 UTC
Last online:2022-11-23 07:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-17 08:47:11 UTC to abuse{at}amazonaws[dot]com)
Takedown time:5 days, 23 hours, 10 minutes Bad (down since 2022-11-23 07:57:45 UTC)
Tags:AgentTesla link exe opendir rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-21n/aexe 5ff4c3eb0ad5b96bf4f88fa2a99b2589275daebca86e03f904767221839dff63n/aAgentTesla
2022-11-19n/aexe d9737abe95686b73b24bab3b431da3d9a774393f8a228265eb7d4bd6b0f992ddn/aRemcosRAT
2022-11-18n/aexe a202a3843b54121f7d345b48af88393440cee64240dda50ece88cb7bd395b71cn/aRemcosRAT
2022-11-17n/aexe 8229d257d6699ced69f12743b735628872ca89d62501ea4283d976206e4b10deVirustotal results 31.94%RemcosRAT