URLhaus Database

You are currently viewing the URLhaus database entry for http://79.110.48.52/ngtow.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2714965
URL: http://79.110.48.52/ngtow.vbs
URL Status:Offline
Host: 79.110.48.52
Date added:2023-09-29 08:00:10 UTC
Last online:2023-10-16 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-09-29 08:01:06 UTC to abuse{at}rocketdedi[dot]com)
Takedown time:17 days, 5 hours, 12 minutes Bad (down since 2023-10-16 13:13:14 UTC)
Tags:vbs

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-13n/aunknown db2da5a9ec0d7a9bc00d7e0f297b0ea4667020127fa2214e955fbd1169039726n/a 
2023-10-11n/aunknown c082245ec6686fec7ff67f832f254b414ccf8d4adffc9c729fb827c406f83b0dn/a 
2023-10-10n/aunknown 1fa1f8c27b82c3f8b66ebb479b416d8d91ae41d447469a25761027572d3d1ae3n/a 
2023-10-09n/aunknown 0656539206ce5bd239cab2b588308447840cf8ea5e4ef9428d5929a7a3d7534bn/a 
2023-10-06n/aunknown 1886eebeb617af73c3a2b61354a1dca429a9a4041411e0211aaea1f73159d81en/a 
2023-10-04n/aunknown 385caeb453f1fea11eb94e578f5270617fcbb4361c4496ab746248525ebca9can/a 
2023-10-02n/aunknown 20acb9f11194474079577acf1b1a45d72d59496c2f4350fec0f8de764bbd6d53n/a 
2023-09-29n/aunknown 7fb3e0f3f2c6d21f69a41cbe40eb64bfabc75cc30710cdf5a15cdbdd91d0785fn/a 
2023-09-29n/aunknown 6f38a1a6a3e171d6e847c30454bbeb1208b615204b5c7349f91818c9a11d4ee1n/a