URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.65.80/rinkas.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2716312
URL: http://5.42.65.80/rinkas.exe
URL Status:Offline
Host: 5.42.65.80
Date added:2023-10-04 08:06:05 UTC
Last online:2023-10-15 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: Casperinous
Abuse complaint sent (?): Yes (2023-10-04 08:07:04 UTC to abuse{at}lethost[dot]co)
Takedown time:11 days, 12 hours, 49 minutes Bad (down since 2023-10-15 20:56:50 UTC)
Tags:Amadey dropped-by-SmokeLoader LummaStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-10-12n/aexe 58a3a12bad866167a10eaf1511fedf0d8759533880f040a4a6d7bbb8a348e448Virustotal results 59.72% Backdoor.TeamViewer
2023-10-11n/aexe ddc3ba21d70f788998930254d4a47ee0ce69f494b6f96d804ed55de8123e4bbaVirustotal results 59.72% Backdoor.TeamViewer
2023-10-11n/aexe 2d91d570352bd6a65a8dfdf72bcf4bf1ed353c8f4310aabd4b77b31e1e98c831n/a Backdoor.TeamViewer
2023-10-10n/aexe f30654f4b2b72d4143616a3c2bb3b94b78a9726868b3dfa302ba36892e889d0eVirustotal results 58.33%LummaStealer
2023-10-10n/aexe 89b23431a3fd1b1932a26c626dbf5ad39d5a82fcc10ca4fd20e4d90f635bda42Virustotal results 60.00% Stealc
2023-10-09n/aexe 28c7a1e748b19f24cbd60e3391636e66c29243bec0414c4a839183b8ed439425Virustotal results 59.72% 
2023-10-09n/aexe b8b8bd658fc2c59179feb45647839521608a37e3f67c1357e3d2dc76fa9828e0Virustotal results 59.15% Backdoor.TeamViewer
2023-10-04n/aexe 563acabe49cc451e9caac20fae780bad27ea09aaefaaf8a1dfd838a00de97144Virustotal results 87.50%Amadey