URLhaus Database

You are currently viewing the URLhaus database entry for http://103.77.241.135/cbot/cbot.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3737810
URL: http://103.77.241.135/cbot/cbot.exe
URL Status:flame Online (spreading malware for 4 days, 20 hours, 27 minutes)
Host: 103.77.241.135
Date added:2025-12-20 09:48:08 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-20 09:49:16 UTC to hm-changed{at}vnnic[dot]vn)
Tags:ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-22cbot.exeexe 653b90d033d7e977f2161f77f4e70d30eab30840fd1d238eb051e3ea7bc13520n/a
2025-12-20cbot.exeexe 45153e2ab3b109dddc846c01c4fa8c49afa0c90e5d3e0570813c740c8f0a0283n/a
2025-12-20cbot.exeexe 11607c1211dd50a49b37882ec1dfc5d187bfff9080892cd5c6fd93c0d80877c7n/a