URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.66.22/retail.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2786257
URL: http://5.42.66.22/retail.php
URL Status:Offline
Host: 5.42.66.22
Date added:2024-03-18 14:08:59 UTC
Last online:2024-03-30 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-03-18 14:09:07 UTC to abuse{at}lethost[dot]co)
Takedown time:12 days, 7 hours, 53 minutes Bad (down since 2024-03-30 22:02:35 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-30Retailer.exeexe 4c5acfbc4d264d8c97572426fd9c899f79594fde436ff9d45de81ded5e14a059Virustotal results 31.94%RiseProStealer
2024-03-29Retailer.exeexe e5ec6a2e160be8051aeccdf5458c460309856ae709ef3fc626f944ba61d56975n/a RiseProStealer
2024-03-28Retailer.exeexe 8aa32a4fd85c39bba4174a3d8abdf4cdc6cac95537868a41684bbc73e2ff59b4n/a RiseProStealer
2024-03-27Retailer.exeexe 5c8618b4628653d6edec64f21b5bc96f5698a0829e3245d3a8852dd37e2cb090n/a RiseProStealer
2024-03-26Retailer.exeexe 75b7f07c0edd9d89794a83ed09375b59665fd6539c984f506acb099893374d74n/a RiseProStealer
2024-03-25Retailer.exeexe fe6c3c6635051a7c1e0f53bea9a84fbbe9d46e89736995468c1eb636f9fc3708Virustotal results 26.76% RiseProStealer
2024-03-24Retailer.exeexe 68caff9f89b8899d1e6c536bc900de0e2aeccf47a0629eab58e4e92e9f79a124n/a 
2024-03-23Retailer.exeexe 511a36d087966f2474d912bc47e8216855edf7fc16525a5e60097c756a2083d6n/a 
2024-03-22RiseRetailer_1.7.exeexe 742754c4fb88d4d4b741994bde455e45c9efa3f0ffb7823c7284623b717595a6n/a 
2024-03-22RiseRetailer_1.7.exeexe 2756ddc24d2f9695563da826a7351bbf13a01febe2a03b7a00d62b9f3f5807d2n/a RiseProStealer
2024-03-21RiseRetailer.exeexe c8ecad86d9a9a95b28a79f974c4407b44983b574c14bfea4cfc858b7701b6cfan/a RiseProStealer
2024-03-20crypted_5aacadb9.exeexe 1149d21cd165e15102848579f668afbe076a07fa5524d0f231ec21cc5bffee8an/a 
2024-03-19RetailerProxy.exeexe bd81aacc34212fdc8bd7f0788e850e8e95cca31db5906ca926eb505cec8fcb9dn/aRiseProStealer
2024-03-18RiseRetailer.exeexe 3c4012350ec5a99f3daf11bb1e39784247290b18c7073ab4bea14d657107fe71n/a 
2024-03-18RiseRetailer.exeexe f6dddbe18895719a899361ec8b464d9277c8cbe0d4aa44427fe76a617f8a3e54Virustotal results 28.77%RiseProStealer