URLhaus Database

You are currently viewing the URLhaus database entry for http://23.94.99.117/5428/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2538577
URL: http://23.94.99.117/5428/vbc.exe
URL Status:Offline
Host: 23.94.99.117
Date added:2023-02-13 09:03:11 UTC
Last online:2023-03-22 10:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-02-13 09:04:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 month, 7 days, 1 hours, 36 minutes Bad (down since 2023-03-22 10:40:12 UTC)
Tags:AgentTesla link exe RemcosRAT link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-20n/aexe bb4297e1d60fbf0c9670f3a436d3c00993307ccf5bbf9bade4a6ebcb608edd6cn/aAgentTesla
2023-03-20n/aexe 5fc747d77faaedb0459b4e9fb8dbef1912f6fa91ad088a3ec016c749ecd83022Virustotal results 40.58%AgentTesla
2023-03-20n/aexe 66d51327bab933eda9d755eb691e584fcb324b04c573d1be50d634c7297134f8n/aAgentTesla
2023-03-20n/aexe 65cc1ea27c733c270dd0497ed9c99896baf50eeafa5e1200889557985bfd87d5n/aAgentTesla
2023-03-18n/aexe 2d375d705eba9a464fd1ebd8d4f15adf3e7e62b16fb0f5b41f96d1872040edf7n/a
2023-03-02n/aexe 02ced6da9cf24901681948deae308d36975cb623dcc6735f2142f4252bc7e197n/aRemcosRAT
2023-03-01n/aexe 9f9f3096c804ba3921cfbdbcc3e2f877ab7d3f5f0e2d264be739c485fd02ccd8Virustotal results 32.31%RemcosRAT
2023-02-13n/aexe e1cfaf8c115404150c4bae0e2210c47862cdc5f12b0e2054bd5afd4ce6569737n/aSnakeKeylogger