URLhaus Database

You are currently viewing the URLhaus database entry for http://103.125.189.50/documment/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2428666
URL: http://103.125.189.50/documment/vbc.exe
URL Status:Offline
Host: 103.125.189.50
Date added:2022-11-21 15:19:33 UTC
Last online:2022-11-25 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-11-21 15:54:07 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:3 days, 8 hours, 29 minutes Bad (down since 2022-11-25 00:23:50 UTC)
Tags:exe Formbook link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-24n/aexe db4f7ae9934ea4c650e8f3efbab3914b4c37cfb74d3da221a2c767db3a739dd9Virustotal results 19.72% 
2022-11-23n/aexe 697864448562120dd68a9b3a4c36f294292626999e3c80d3217206544e3f91b1Virustotal results 36.11%Formbook
2022-11-22n/aexe 62c12178f0076c41d2960d039ba55525bc398b935db8662e0f8d7f5089e34359n/a 
2022-11-22n/aexe 1f3edb430ef26e7987d8b073a0314ee9632bc2d57767083eafeddf9209ade01dVirustotal results 35.21%Formbook
2022-11-21n/aexe 3a61280726d90b185f70884c4f7ff84af52be06f7fa2ceebf16065e8aee4feb6Virustotal results 30.99%Formbook