URLhaus Database

You are currently viewing the URLhaus database entry for http://192.3.101.163/4020/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2554574
URL: http://192.3.101.163/4020/vbc.exe
URL Status:Offline
Host: 192.3.101.163
Date added:2023-03-01 19:03:12 UTC
Last online:2023-03-03 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-01 19:04:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:1 day, 11 hours, 14 minutes Poor (down since 2023-03-03 06:18:47 UTC)
Tags:AgentTesla link exe opendir SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-02n/aexe bc3278a0b906345cc7501a28fc5b4addbc862edf1ba611d033113d97cdc02af5Virustotal results 35.71%AgentTesla
2023-03-01n/aexe a46f5213113d894ca3e9dc9ec6d66ab9e46253d05d08a035a0e2e817744047a2n/aAgentTesla
2023-03-01n/aexe b97359d81ff705942e503b8a9636d0260a6de0d6c7d00fe6a104e6413eebf5b6n/aAgentTesla