URLhaus Database

You are currently viewing the URLhaus database entry for http://103.77.241.135/cbot/raw_cbot_debug.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3737808
URL: http://103.77.241.135/cbot/raw_cbot_debug.exe
URL Status:flame Online (spreading malware for 4 days, 15 hours, 55 minutes)
Host: 103.77.241.135
Date added:2025-12-20 09:48:08 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-20 09:49:16 UTC to hm-changed{at}vnnic[dot]vn)
Tags:ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-23raw_cbot_debug.exeexe 4f39228fbb939d092bb54f17f8aa9ebda4869607bb9cfd5609ed7beeb0faba65n/a 
2025-12-22raw_cbot_debug.exeexe aacaf35dc2a32607acd739bb040705501f4dc99f19537b9e76b8323d05b968d8n/a
2025-12-20raw_cbot_debug.exeexe 60ad592e7c6ae8922ec84c0797fb0c4ac631e962c8ed95e270b2a7ee12ad4a80n/a
2025-12-20raw_cbot_debug.exeexe 1c1ea4b5f12a991ba2689d1772ff795df8c7513e296b557821ae3f45de8ea170n/a