URLhaus Database

You are currently viewing the URLhaus database entry for http://79.137.192.18/rock.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2706590
URL: http://79.137.192.18/rock.exe
URL Status:Offline
Host: 79.137.192.18
Date added:2023-08-24 03:26:12 UTC
Last online:2023-09-02 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-08-24 03:27:06 UTC to abuse{at}lethost[dot]co)
Takedown time:9 days, 18 hours, 46 minutes Bad (down since 2023-09-02 22:13:27 UTC)
Tags:32 Amadey exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-08-30n/aexe 673192e23603b5a23173abeb594103e7babf154eb3af5288ccfb0fa6db6eacf5n/a Amadey
2023-08-27n/aexe 3bda837b7567cc5917c300ca3360d91434bf002656f1504276aa700ccfb5ca90n/a Amadey
2023-08-25n/aexe e8911bb8e59c1b64ec8c6867ee2be66ed5b39c584ce80ffbbdf8640ccbcae65bn/a Spambot.Kelihos
2023-08-24n/aexe 5f28b73d46cfd9702df5c1991aad67eff91c69ed2ba9bbc7dc5e14c74168d2eeVirustotal results 60.56%Amadey
2023-08-24n/aexe 76e0a05722db609c2d5fc63f43fd52e093404f10f14722aa7f44fb967d2f153cVirustotal results 71.83%Amadey