URLhaus Database

You are currently viewing the URLhaus database entry for http://79.110.48.52/kenpol.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2711984
URL: http://79.110.48.52/kenpol.vbs
URL Status:Offline
Host: 79.110.48.52
Date added:2023-09-16 07:09:06 UTC
Last online:2023-10-16 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-09-16 07:10:09 UTC to abuse{at}rocketdedi[dot]com)
Takedown time:1 month, 0 days, 5 hours, 47 minutes Bad (down since 2023-10-16 12:57:42 UTC)
Tags:Formbook link vbs

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-12n/aunknown 1f1aa89a80dc919eb1db9c8775eef75cb1f14450c182aac1391bc1ca3a194da1n/a 
2023-10-10n/aunknown 36fe906a8c40107acf47d1138dff0807f6a5ebff753f10c6883a661639896c67n/a 
2023-09-28n/aunknown 9fd85511cbc4c6e3336f1a9bb3bd38e8ff46e3ccddfd1799b0bc0ed3a24dc05an/aFormbook
2023-09-27n/aunknown 83dfab9427289c9c30c6975a149645d0baa4d8e5de432a15153374b210fef5b5n/a 
2023-09-25n/aunknown 144ad00305cc9a1652259a9898ddda8f5cea824e5234d4f6f05a1515cea8951bn/a 
2023-09-21n/aunknown 7d805566e4432938bc049227aed209e620f802f4d088a9e9400a40cd6d788a23n/a 
2023-09-18n/aunknown 58d1ce2f65418b5b023509984b4551e85f2dcfabfd636479d7805ffe408a0d4an/a 
2023-09-16n/aunknown 273804a14b2ecc53eae5edeb8abc69372bbe1d5ae31367e1b904c9de6026dcd1n/a