URLhaus Database

You are currently viewing the URLhaus database entry for http://peak-tv.tk/wealthzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1970035
URL: http://peak-tv.tk/wealthzx.exe
URL Status:Offline
Host: peak-tv.tk
Date added:2022-01-12 07:42:05 UTC
Last online:2022-02-23 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-01-12 07:43:07 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 12 days, 0 hours, 28 minutes Bad (down since 2022-02-23 08:11:07 UTC)
Tags:AgentTesla link exe SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-22n/aexe 67784d22999926733d9461e2884fbbc19833706958db7d9d4b27ce2e903f45d0n/aSnakeKeylogger
2022-02-17n/aexe fb8c3859b64cab452d77c56d6ed7ebcbe49fa5ab38f1590b41ee702ff118acb9Virustotal results 55.07%AgentTesla
2022-02-08n/aexe 02b32b969ac78b0bb3caf5ecd061f54b5aef5590584e74a6a5537551f6aca83an/aAgentTesla
2022-02-08n/aexe fe6f9a95005294aa99467b4df9e2130eec3a4d396555b8bb114a917d4c7b0316n/aAgentTesla
2022-01-28n/aexe 4a68b2f28a4e26052bc91d0ce5050712f19b1a57a4a1ecc12de75bad8cac331fn/a 
2022-01-21n/aexe f11ab395547ecacdcc66bd98f1006c3f9fd1ae42272ec5c9c9376a0657b58947n/aAgentTesla
2022-01-20n/aexe dcc30daa103f38a83d8f731cf1d6dccdfd53d20e27b6944fd328cd78149beba8n/aAgentTesla
2022-01-20n/aexe c57fe1ed5d41144d82c9892c688982e7a649e4c3be7c130b48fbd13949448e7bn/aAgentTesla
2022-01-14n/aexe 8bb6b86fd0eca5a4daf60d4115bfe882634ed50a799234ecb6d85580b68280bbn/a AgentTesla
2022-01-12n/aexe 1dc9f8c0a33411c36c72c95065e0860a60be4ebb1cd7f46eab7eaec6ec676a79n/a AgentTesla
2022-01-12n/aexe b5347abcba9dfc9bdcf610bd8feee1128d9703de3b46f81d3767b9570c9b1babVirustotal results 35.82%AgentTesla
2022-01-12n/aexe 250070f0300deead62b159b05cd272fb818ec06a3b7761a41d3a366c365cb6f0Virustotal results 34.78%AgentTesla