URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.66.0/newrock.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2746968
URL: http://5.42.66.0/newrock.exe
URL Status:Offline
Host: 5.42.66.0
Date added:2024-01-06 12:23:14 UTC
Last online:2024-01-12 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-01-06 12:24:13 UTC to abuse{at}lethost[dot]co)
Takedown time:6 days, 3 hours, 4 minutes Bad (down since 2024-01-12 15:28:19 UTC)
Tags:32 exe glupteba link Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-01-12n/aexe 5442c4d8a345d663bae3777cd3478bd8a82fed51f8f27b5171ba48559477524cn/a Stealc
2024-01-10n/aexe 1840980cb9795e0e2e25a35df5af4d0405e594bbf2c60abd29f2facf2fe9fe5cn/a Stealc
2024-01-09n/aexe 785d58d4bfaa254c9cafd37fafa01d9122e9c8036f5f407d4d277ce121fe2cc8n/a Glupteba
2024-01-09n/aexe 4436e908111bd5641201fec0b80656609cda5c3d189a5f5e8c3fde69a50f88dcn/a Glupteba
2024-01-08n/aexe f5ef6f1272125d6166ac834f0dc7d9b3a180376842d2f77364b8f9d148161fa2n/aStealc
2024-01-07n/aexe ac2f25abe3976c01ff6792b10b6bc148fb7ee55ce332cf2e90af1dfce5aca928n/a Glupteba
2024-01-06n/aexe b9123eff82d12c62b247a51cdb9ea2b166d38f1ec8dba8b6ef9be868e44eda15Virustotal results 65.22%Stealc