URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.41/ikmerozx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2132671
URL: http://2.58.149.41/ikmerozx.exe
URL Status:Offline
Host: 2.58.149.41
Date added:2022-04-05 12:36:04 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-04-05 12:37:06 UTC to abuse{at}serverion[dot]com)
Takedown time:3 months, 12 days, 4 hours, 36 minutes Bad (down since 2022-07-16 17:14:02 UTC)
Tags:AveMariaRAT link exe WarzoneRat

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-13n/aexe 4c80b15f618430bbdf83f50f013a96c559f99effbfb0a8812f10bfddd086064bn/aAveMariaRAT
2022-06-09n/aexe 20ab79cda3405249b033bd19bf4e7de25797664e8ae54d781ae36f28236c15den/a AveMariaRAT
2022-06-09n/aexe 30e66e726d81b1f3fc5c48b7e619812b5682769ef9fd5e4be98706f58850b360n/a AveMariaRAT
2022-06-08n/aexe ac687e9f044af0ff976bffda1e272e9b8aa6a88ecbd1944594ca67485ddc6b87Virustotal results 38.24% AveMariaRAT
2022-05-13n/aexe 17f010ef410c5b3862600e5bb68ed50701dabf89bdf47fde54855cd1a2ac1778n/a 
2022-05-02n/aexe 9ac06de0ab3464aefa19a385a38369f069ff6ceee10a2e35691d0e3a2dd5f4e2n/aAveMariaRAT
2022-04-12n/aexe 541fbec081719c440d95155189e5f90573351b94bbae41393656e91ca641bffan/aAveMariaRAT
2022-04-05n/aexe cc20314107f1e2d9f2952d28176893e1123dfa3f44bd1b089a9477b60dcf5b3fn/aAveMariaRAT