URLhaus Database

You are currently viewing the URLhaus database entry for http://216.170.114.70/regasm/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:882338
URL: http://216.170.114.70/regasm/vbc.exe
URL Status:Offline
Host: 216.170.114.70
Date added:2020-12-02 10:42:05 UTC
Last online:2020-12-31 06:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-12-02 10:44:04 UTC to abuse{at}colocrossing[dot]com)
Takedown time:28 days, 19 hours, 32 minutes Bad (down since 2020-12-31 06:16:15 UTC)
Tags:AgentTesla link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-31n/aexe a7d250d16e52be594a0dc8292110a3bab73b77840e011f6e90c637a674fe5600n/aAgentTesla
2020-12-30n/aexe 0d18d3ad450d2c0b56cc07a890d32b45bec36dc3c1ee28a0affd530687701eean/aAgentTesla
2020-12-30n/aexe 484a8627e58d52623e67f88d6e90a2bd5e81a234dd3e1a528b42d30480b67f7an/aAgentTesla
2020-12-29n/aexe 4a3724a895ab336e183024862925d0ad6d66eff5eb8a1bae8c45afc004e65157n/aAgentTesla
2020-12-28n/aexe 07d5f066f676954e18d83828bca1f87947ef5612997aa09f63c6abb992150225n/aAgentTesla
2020-12-28n/aexe aec5dbe1cc640224304080438ca877932016e4710c12b649e9aae03901e36a2eVirustotal results 35.21% AgentTesla
2020-12-10n/aexe f2436a308e6189128401819fbb1f60f7094e3843bd2f3902739f545b29eda2a7n/a
2020-12-09n/aexe 3ef39c4ba30114688584f0d34d5c4238fba9e5fe3f3e405d38109eb2a4619576n/aAgentTesla
2020-12-04n/aexe 683478f861e01bef5ec49d9ecdeaafd9c156811fc2e7b0acf28f2c9ea0d0fcc1n/aAgentTesla
2020-12-03n/aexe 3700a970f0388eab91ae394304a67b22ed4132e47c6037805c175c9e9ea1d0d9n/aAgentTesla
2020-12-02n/aexe 0ea9918fde5a26af008b03a8f9dbccb1e48070ab92b8ae0651f1e80fb8dbce3an/aAgentTesla
2020-12-02n/aexe ac84fce48dc5fc0ece582c6cd8f5486d044f48f2923e949d27c5ea44cb0a80a0n/aAgentTesla