URLhaus Database

You are currently viewing the URLhaus database entry for http://23.227.207.253/hkcmd/vbc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:978932
URL: http://23.227.207.253/hkcmd/vbc.exe
URL Status:Offline
Host: 23.227.207.253
Date added:2021-01-26 13:38:05 UTC
Last online:2021-01-28 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2021-01-26 13:40:08 UTC to abuse{at}hivelocity[dot]net)
Takedown time:1 day, 20 hours, 10 minutes Poor (down since 2021-01-28 09:51:06 UTC)
Tags:Formbook link VelvetSweatshop

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-27n/aexe 9d50392282682d4b8c106cc20b924427e2cd48863f8e88e8c841bcefc7e03d05n/a 
2021-01-27n/aexe c25dae1e3e6c72b36cf02a2a2eaaf3ee5c29b6e2b0cf1da64c3f521be54dc5e9n/aFormbook
2021-01-26n/aexe 5f42f68bc67c97ebf181c31e7c243eee3580ebc75bb2a277f1847ea2bcedecc3n/aFormbook
2021-01-26n/aexe 2d14644ecb7e3d6a7f6e2c8888ecda848a2a9dbf30dd534c5aa531a5c4bcef2en/aFormbook