URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.41/psmzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2111682
URL: http://2.58.149.41/psmzx.exe
URL Status:Offline
Host: 2.58.149.41
Date added:2022-03-23 04:33:04 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: AndreGironda
Abuse complaint sent (?): Yes (2022-03-23 04:34:05 UTC to abuse{at}serverion[dot]com)
Takedown time:3 months, 25 days, 12 hours, 40 minutes Bad (down since 2022-07-16 17:14:18 UTC)
Tags:AgentTesla link AveMariaRAT link exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-15n/aexe d83aa0f6cae89cd0af385215ba7b08b997f876a1c87b60a14ff05fe1e1dccb8aVirustotal results 55.88%AveMariaRAT
2022-04-13n/aexe a214eab4e3b84f641d8c0e8bc9a7421da61260088b2b5e2a5da32ebdf29e9213n/a AgentTesla
2022-04-11n/aexe 62cb6977571673131e19fb967260bbe11d225a79197cba0f78ced3cf9b0b2fean/aFormbook
2022-04-08n/aexe 123029d80a1c5897367e0b1b48838658d4a36415c9146e552f15d16389886e11n/aFormbook
2022-04-06n/aexe c54c67f6994056e89d4c041287ba3780d0c471418b6f3ff532a5e69a77169cb0n/a Formbook
2022-04-05n/aexe d7d5842b7eed6386f41f307b5de1e9b4350fbd21c26eccfa1345ff3a349d9f52n/aFormbook
2022-04-05n/aexe e510ae88a77d3b9e8b63eb2289768a64c3637a16efd9655318942ddae1ec40e9n/aFormbook
2022-04-05n/aexe 3535000ea4f4d1d567325cefa78695a5bc99e352e155cde1e385b5be0d235d2cn/a Formbook
2022-03-23n/aexe 43aa2b7f94d0424b6c99c46dc9a1a95cb0ab88b498d24e6197755a585063b2ban/aAgentTesla
2022-03-23n/aexe ddcb778598a4921123f8661e0671197438d10c909373a120143a97bbce04a73bn/aAgentTesla