URLhaus Database

You are currently viewing the URLhaus database entry for http://23.94.99.117/3591/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2563450
URL: http://23.94.99.117/3591/vbc.exe
URL Status:Offline
Host: 23.94.99.117
Date added:2023-03-08 21:09:06 UTC
Last online:2023-03-25 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-03-08 21:10:10 UTC to abuse{at}colocrossing[dot]com)
Takedown time:16 days, 9 hours, 5 minutes Bad (down since 2023-03-25 06:15:52 UTC)
Tags:AgentTesla link exe opendir rat RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-17n/aexe 2e88105d979bfbe65b2ed9322114fc21ef9e1fdb324a63d6198defd1e976d36en/aAgentTesla
2023-03-16n/aexe 462b121f72bc42fcefcfc67174e4de53083b977458c7ed3d4009eec6bddd3f1bVirustotal results 33.33%AgentTesla
2023-03-09n/aexe 78b009999d967e2d3eeb4a10ce91c84048dc566d2a74d8e223a6a5b15db5839bVirustotal results 15.94%RemcosRAT
2023-03-09n/aexe 14f6d15b3a4940f6cbda03673df4867785286b798c87d36ece18ddccd5dce084n/a RemcosRAT
2023-03-09n/aexe 9184cd81781503972e53fc34d26c401e791b6425b25a78473e369ec4a97ac7a7n/a RemcosRAT
2023-03-08n/aexe cf6de5f333dea0ffbc94ef944a23c99db28e66e7d51757d01a9a017a21fb8837Virustotal results 34.78%RemcosRAT