URLhaus Database

You are currently viewing the URLhaus database entry for https://unionbindinqcompany.it/vbs.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2518821
URL: https://unionbindinqcompany.it/vbs.exe
URL Status:Offline
Host: unionbindinqcompany.it
Date added:2023-01-26 07:33:17 UTC
Last online:2023-02-13 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-01-26 07:34:06 UTC to abuse{at}netim[dot]net)
Takedown time:18 days, 3 hours, 0 minutes Bad (down since 2023-02-13 10:34:58 UTC)
Tags:exe Formbook link rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-02-08n/aunknown 1a6ee6bdd10a2f6067cfbdd6d9b5b2a6ff7e8d83a69390225474bd524b33c3b5Virustotal results 0.00% 
2023-02-07n/aexe 8006ab2944380f5aa422230ba36c98f4476f7e9fbce7c128875510ff3ab65a45n/aFormbook
2023-01-31n/aexe a6bdc7d25ae942d15182d26e449c329340db53470a079647d3b6ddb06b7e28d5n/aRemcosRAT
2023-01-31n/aexe de8a8e788979f605ae68981ec3bf84711e957bfa4746d5f23c2015a8ec928c32n/aRemcosRAT
2023-01-29n/aexe c834570ccd6b2682beabbfc8d40e992d52f386aa4542edb5f171250d6f1cb549n/aRemcosRAT
2023-01-26n/aexe 69b7150f7be7cfd685c50328e9554d28d99e9f7babdf19eb10ea350a3658f2acn/aRemcosRAT
2023-01-26n/aexe 032f8672b774c3a0edd3b84b0f809e1901319a2b0a4a60704e75f92bdac4f7bbVirustotal results 25.71%RemcosRAT
2023-01-26n/aexe 23dd65161a7f297125c40f5c9e12d9c0bc9c314021a74de9d47ec8bc13146b18Virustotal results 27.14%RemcosRAT