URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.66.22/getimage.php which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2788956
URL: http://5.42.66.22/getimage.php
URL Status:Offline
Host: 5.42.66.22
Date added:2024-03-21 15:12:13 UTC
Last online:2024-03-30 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2024-03-21 15:13:07 UTC to abuse{at}lethost[dot]co)
Takedown time:9 days, 7 hours, 5 minutes Bad (down since 2024-03-30 22:18:16 UTC)
Tags:dropped-by-PrivateLoader RiseProStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-03-30Arab.exeexe bc22b31072421cde9ebfddd19be474c242974eab90b475f845ee463c79176548n/a RiseProStealer
2024-03-29Arab.exeexe d783cf4b7e5773017a293a4316e98c2bb9ec77e1fe36e93e3aa8edc418b14b31n/a RiseProStealer
2024-03-28Arab.exeexe c9f849ba8e54be05b1cbc63afdf468beae2810a70230d212b8c1e997110ec015n/a RiseProStealer
2024-03-27Arab.exeexe 81031d876f36d8ca2f1b73aa8bde63134c66f60991070b183e2c1f40463d695cn/a RiseProStealer
2024-03-26Arab.exeexe 97a45356a21df6900370d01e46b54936215535592e74510c0a4742854aa9a5c5n/a RiseProStealer
2024-03-25Arab.exeexe d78fdeb9598011de039128e779318411171f896486f059d723b70cd4944787a7n/a RiseProStealer
2024-03-24Arab.exeexe a84bfb4e378224cce70975bcfc0e3dd82ee09fc107d8e1f697ec99bf4e778858n/a RiseProStealer
2024-03-23Arab.exeexe 164571f6f5a1bd92f58132940aac67abf01dde90bdc72dd5f4e3aa0618670048n/a 
2024-03-22RisePro1.7.exeexe bb287aafd9b9246e191cd738bf519a80eb25b53c24b0ffc5946cfc47114482c8n/a 
2024-03-22RisePro1.7.exeexe 9c3f792443e10305f566f6ea9b2c0b3e552c8a7e093e6a6a589d9f59843313afn/a RiseProStealer
2024-03-21RisePro1.7.exeexe 4ea66bce328651a434742a5217297822bc5a594e7fab1aa6845c6135028ff9f6Virustotal results 40.85%RiseProStealer