URLhaus Database

You are currently viewing the URLhaus database entry for http://198.46.177.210/125/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2514016
URL: http://198.46.177.210/125/vbc.exe
URL Status:Offline
Host: 198.46.177.210
Date added:2023-01-21 03:22:06 UTC
Last online:2023-01-24 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-01-21 03:23:07 UTC to abuse{at}colocrossing[dot]com)
Takedown time:2 days, 23 hours, 48 minutes Poor (down since 2023-01-24 03:11:58 UTC)
Tags:32 exe RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-01-23n/aexe 46c51fd18a7a62b46a59a11cd3192adf716b3abbf4213352224ee1d57dc3e46en/aRemcosRAT
2023-01-22n/aexe 7bc48731d6206024b65d1b96d931ebcda37dd166352f2c0bb34ffc9fc73cd51dVirustotal results 44.29%RemcosRAT
2023-01-21n/aexe 03c376f93694b16411d767bd648451d76eb1e472511a96c421a9e50089cb239bVirustotal results 34.29%RemcosRAT
2023-01-21n/aexe 8fbb20cfaa8c33580a1d174eb1696a27e47ba7c81762c1bac0a98be22f2d07eeVirustotal results 43.66%RemcosRAT