URLhaus Database

You are currently viewing the URLhaus database entry for http://chidieberedanielegbukasingaporemonni.duckdns.org/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:333083
URL: http://chidieberedanielegbukasingaporemonni.duckdns.org/vbc.exe
URL Status:Offline
Host: chidieberedanielegbukasingaporemonni.duckdns.org
Date added:2020-04-01 06:54:05 UTC
Last online:2020-04-15 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: gorimpthon
Abuse complaint sent (?): Yes (2020-04-01 06:56:05 UTC to abuse{at}colocrossing[dot]com)
Takedown time:14 days, 2 hours, 2 minutes Bad (down since 2020-04-15 08:58:58 UTC)
Tags:Agent Tesla link AgentTesla link exe GuLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-15n/aexe 2fd910434e03291b8aa3720b5d9136e3d504224f1cdb69d63e06753cfa82f085n/a AgentTesla
2020-04-02n/aexe 2aa324195b641499159816aa2ba8f40f6c5d971bcbee5a753d330df383867248Virustotal results 18.31%GuLoader
2020-04-02n/aexe c2e79c671de8e641877d8526d27b901122f1d486dae5e15da42b51c1276aace4n/a AgentTesla
2020-04-01n/aexe 016986606ce9c15d4c56ade566547178f3db45c7d94fe26d7efd375cf799f923Virustotal results 26.39% AgentTesla