URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.65.80/ship.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2715038
URL: http://5.42.65.80/ship.exe
URL Status:Offline
Host: 5.42.65.80
Date added:2023-09-29 11:50:16 UTC
Last online:2023-10-15 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-09-29 11:51:05 UTC to abuse{at}lethost[dot]co)
Takedown time:16 days, 8 hours, 57 minutes Bad (down since 2023-10-15 20:49:02 UTC)
Tags:Amadey exe LummaStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-12n/aexe 563acabe49cc451e9caac20fae780bad27ea09aaefaaf8a1dfd838a00de97144Virustotal results 85.71%Amadey
2023-10-12n/aexe 97931886c3b7609b59afb16d53a5a689c210b15e2c28a75fae75a6f9ceb4348dn/a Backdoor.TeamViewer
2023-10-11n/aexe 5db152a22827f1e105d6aa98166dd30338930eacbd1bf2e7c6e74cf10334e7c1n/a Backdoor.TeamViewer
2023-10-11n/aexe 5a08584edc12c1469580d4ddb2b0ceaa8a8b212c62e715bed845bd59d6f83331n/a Backdoor.TeamViewer
2023-10-10n/aexe 8f3054ea1c4adfcafc009a413324aec4d47357384e1f57c08a4cdc8ec3863826Virustotal results 58.33%LummaStealer
2023-10-10n/aexe abf143f53b0c5c36e4d9614f77e12c6a070dbe8e38307a0647acae090a0d1bacn/a Stealc
2023-10-09n/aexe 4a8c18ee86bede3f5bfe55b5646e2676067b80ac802513186e7327577b3e9f73Virustotal results 59.72% Stealc
2023-10-09n/aexe 472a7897cd5566dcbf76702343eafb5bff6390f679965a22361eecffeadf4e80n/a Backdoor.TeamViewer
2023-10-09n/aexe f657ca897cc86da03b5378c9740d565abc8b1bcc6481915a2d28ebc170bbea4cn/a 
2023-10-08n/aexe a754eb655af6114a85fe5d32bc3a42b0038fec86c2d557fef2d3f2f92d68b942n/aStealc
2023-10-06n/aexe 7c5048e50bf83c7a281f471425276e6a80b2089ddd85bf5e843a6c06184daf0an/a 
2023-09-29n/aexe 88921dad96a51ff9f15a1d93b51910b2ac75589020fbb75956b6f090381d4d4fVirustotal results 63.89%Backdoor.TeamViewer