URLhaus Database

You are currently viewing the URLhaus database entry for http://103.77.241.135/cbot/cbot_debug.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3737809
URL: http://103.77.241.135/cbot/cbot_debug.exe
URL Status:flame Online (spreading malware for 4 days, 20 hours, 26 minutes)
Host: 103.77.241.135
Date added:2025-12-20 09:48:08 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-20 09:49:16 UTC to hm-changed{at}vnnic[dot]vn)
Tags:ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-22cbot_debug.exeexe b6e366fd0db4b04d765553b13579316918fe19cedad578570a9702014a2569d4n/a
2025-12-20cbot_debug.exeexe 3031ae5cc1b964c06cadf7353a7d34da6d0556b6e2b070bcda532f551c7e3e74n/a
2025-12-20cbot_debug.exeexe 4f6ff3e84e0e766a3741637c53e745fefd72f7186fd617b10a98c27d794dadabn/a