URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.41/mannzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2097009
URL: http://2.58.149.41/mannzx.exe
URL Status:Offline
Host: 2.58.149.41
Date added:2022-03-14 20:02:03 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: AndreGironda
Abuse complaint sent (?): Yes (2022-03-14 20:03:07 UTC to abuse{at}serverion[dot]com)
Takedown time:4 months, 3 days, 21 hours, 14 minutes Bad (down since 2022-07-16 17:17:30 UTC)
Tags:AZORult link exe Formbook link Loki link RedLineStealer link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-14n/aexe 069ea459cef8681cb8ad4158e52fea53f37e02891c0a53da0f4eb335a9f143ben/aRedLineStealer
2022-06-14n/aexe b9a68b7741ffa5390150392587ff6793168b1ad6e97f05d4b336b826218eeae8n/aRedLineStealer
2022-06-14n/aexe 9e3934740535ec45aaa1d9f7a47cafc668d4f9e8ab2b688515a0a540785e7087n/aRedLineStealer
2022-06-08n/aexe febb978e38144272e6868a6f9eb0a706dd8b84110671c950d8cfc94a782ec375Virustotal results 36.76%SnakeKeylogger
2022-03-22n/aexe d69677b0db3158cf464eb2387497e146e892643ef7b886953d6575ce937960c0n/a Formbook
2022-03-17n/aexe ed3f0ebaf7e2a0e41e1fa77a948134c795aaf31f9813f16d8a65c54354e1a90bn/aLoki
2022-03-16n/aexe 7a9066bddd272c50102198fae4c4bade59f8a33e6c99a5f06330ec0025b2fcb4n/aAZORult
2022-03-15n/aexe 6fd11b4a09db2c2713edbe0bb7536402e7e7bf0255ed7b80c6dc4d934938e327n/aAZORult
2022-03-14n/aexe 456050b3b656fc30777d31163ef1677302f224c4d36bc43dff99ae91fec67d61n/aAZORult