URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.65.80/brandrock.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2731883
URL: http://5.42.65.80/brandrock.exe
URL Status:Offline
Host: 5.42.65.80
Date added:2023-11-18 07:36:11 UTC
Last online:2023-12-03 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2023-11-18 07:37:03 UTC to abuse{at}lethost[dot]co)
Takedown time:15 days, 11 hours, 34 minutes Bad (down since 2023-12-03 19:11:45 UTC)
Tags:32 exe Smoke Loader link Socks5Systemz link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-28n/aexe af28ca70335efa9702faf39ba2f9313123b6453350855b287653151a6b5944e9n/a Smoke Loader
2023-11-26n/aexe 5c130c14c829a8165ae0ce89388f02bbc7fb0a3eb915d88ae9088cebfae1cbecn/a Socks5Systemz
2023-11-26n/aexe 075a1c2838c1f88bd6be4b8450be21c677938f02574e6ea05fe5ef8487cc182an/a Smoke Loader
2023-11-22n/aexe 78bf5f97aac9ed7e988fd919aa5f1212b4712b01aea5892137cc10e13158222an/a 
2023-11-22n/aexe 6f8cac0c8053b3ea09ac50ad61d0fbe673439008af8f612afdf9d7ab17b5a694n/a 
2023-11-21n/aexe 95894fc590395b9ff90289469bcce0182b4845a63af15c97f845b74982b0d0b5n/a Smoke Loader
2023-11-20n/aexe 665a3b9999f1d6716fa1a0a537b1baade26027629da4c8964f011969ea49b0den/a Smoke Loader
2023-11-18n/aexe 8817cbb6de1446a920401a072df1453459aa95684ffc7da9c05ca759b1836c0cVirustotal results 62.50%Smoke Loader
2023-11-18n/aexe 0889831e4c97e94979a7cbafe87f3dcd3106f0be34e85487055bd47df1ca0a57Virustotal results 63.89%Smoke Loader