URLhaus Database

You are currently viewing the URLhaus database entry for http://185.172.128.19/workforroc.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2753145
URL: http://185.172.128.19/workforroc.exe
URL Status:Offline
Host: 185.172.128.19
Date added:2024-01-29 16:11:32 UTC
Last online:2024-02-22 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-01-29 16:12:10 UTC to abuse{at}tnsecurityl[dot]ltd)
Takedown time:24 days, 4 hours, 4 minutes Bad (down since 2024-02-22 20:16:45 UTC)
Tags:RiseProStealer Stealc teambot

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-01-30n/aexe 4c5a5fcfb996dea1c068ea2845c56ba161a881b1f746e194ce38924b38f20b74n/a TeamBot
2024-01-30n/aexe 30b358026a5ac148d0b2c7ad71ca524fbdcbebec70a47b5a50d603499611fc0bn/a Stealc
2024-01-29n/aexe 2fd9b98f1e1908864b32a12a6c9cf3bc0cb66d9b846d699a477a33cd6e84e5f5n/a 
2024-01-29n/aexe 4920d68e17552b9585d4e7195cca6fbd344271aef0cfb48b4e3d898f4a055033n/a RiseProStealer
2024-01-29n/aexe 84d011e18cec6190e2c79b270e9d2d575bfaa63998f50d13d3f9da147f49b799n/aStealc