URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.65.80/rockss.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2712219
URL: http://5.42.65.80/rockss.exe
URL Status:Offline
Host: 5.42.65.80
Date added:2023-09-18 04:43:07 UTC
Last online:2023-10-15 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-09-18 04:44:05 UTC to abuse{at}lethost[dot]co)
Takedown time:27 days, 16 hours, 9 minutes Bad (down since 2023-10-15 20:53:17 UTC)
Tags:32 Amadey exe Smoke Loader link Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-12n/aexe c6b3bded3652afda304198fec2b7e12921b1cf80fc3c76aae6df102eba372905n/a Backdoor.TeamViewer
2023-10-11n/aexe 33d2a9e058659d01f1fa5b752c91aa8e1ab4bac22ec5a1fd2ec1813fe3667238n/a Backdoor.TeamViewer
2023-10-11n/aexe f35aaa60a0cd43454c0416883c855b19da2cb19dfde455c64f41278421e6dcaen/a Backdoor.TeamViewer
2023-10-10n/aexe 7fd0f6e825773d09f3f2233504316d20d3c18fa20c3f8427f9d1db46c69a4740n/a Smoke Loader
2023-10-10n/aexe 7a111775617fd40041aed973937c5e6a975fb7a3a93213318bb6007c01a8d64bn/a Backdoor.TeamViewer
2023-10-10n/aexe 7ce024eccfe9cbd70a597965fea9348511df62e4ed82f2f077d224318c3870cbn/a 
2023-10-09n/aexe a2da4f8ebbc4085821300ac9adb8706ce9cfa283c08895497e519d599654582fn/a 
2023-10-08n/aexe 0c620ad9e0327c9397c2e869a45e3c24cf234f6da22df60ae7fcd802c63d0e8cn/aStealc
2023-10-07n/aexe 25fb255dfc65bca2ca92a3b06ad2e8528c4fd190d6937ae434869e6604453a43n/a 
2023-10-07n/aexe df9200675c836a7edc8c2a9a02da73c7666d9eed96470104f1112d2d61b48a40n/a 
2023-10-06n/aexe 3cb2b7b1b59cc6ace537173608f089cf23da565156cb289e83d41adab31f64bbn/a Backdoor.TeamViewer
2023-10-03n/aexe 563acabe49cc451e9caac20fae780bad27ea09aaefaaf8a1dfd838a00de97144Virustotal results 87.50%Amadey
2023-09-24n/aexe 45584db65038ba23dac7cc37e8314f8e25a8119154f2dd60d42911139437a02eVirustotal results 55.22% Backdoor.TeamViewer
2023-09-22n/aexe 01a7afff3220c1a442e3b8bc41dbf4036e9c223f9aab374265d9beae0709e434Virustotal results 63.38% 
2023-09-19n/aexe 856fc5a591470b6dd10633727130a65d47afed149da52d2c275ef4ef3fdd9856n/a Backdoor.TeamViewer
2023-09-18n/aexe 010fe481ba6275ebbf71e102e66d73f5d819252f2b4b1893d2acf53c04f4200fVirustotal results 63.38%Smoke Loader