URLhaus Database

You are currently viewing the URLhaus database entry for http://45.9.74.80/rocket1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2537391
URL: http://45.9.74.80/rocket1.exe
URL Status:Offline
Host: 45.9.74.80
Date added:2023-02-12 00:38:07 UTC
Last online:2023-03-19 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-02-12 00:39:05 UTC to abuse{at}lethost[dot]co)
Takedown time:1 month, 5 days, 20 hours, 17 minutes Bad (down since 2023-03-19 20:56:58 UTC)
Tags:32 Amadey exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-11n/aexe 48a3255b59e92f99afd5cfb2f7c4336e61aafa1905d7ae5358df9d5cd57cdbc7n/a 
2023-03-11n/aexe 51b52cf60701b991d132d79beaff6f141306ee76b33cba0583d9feb28d01849bn/a 
2023-03-10n/aexe 3fd90c5fdd91598e309a9f661f85d6cf3bcf6d1b792e70224f5889b6533ff1c3n/a
2023-03-03n/aexe ade7d3e8412c5d547caac260f689ad62470c1b125b9e88d5610672c92e5619cen/a
2023-02-24n/aexe e024899665b99b66cafd62c809e354256556d2189aeaf995160849dedb1dc886n/a Amadey
2023-02-20n/aexe 900fa1e6b63833378bd0f1c8931fd31365f3c23b8b6f1f41270f0e9116d82b0eVirustotal results 60.56% Amadey
2023-02-17n/aexe 621a9f892436647a492e3877502454d1783dc0cf4e4ba9f3f459a8c2ac7e6d97n/a 
2023-02-12n/aexe 57fb635fbf142cf0e86cdecc79b16d8b8274b95b3953667c0a557986cb294121Virustotal results 70.59%Amadey