URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.41/wealthzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2142831
URL: http://2.58.149.41/wealthzx.exe
URL Status:Offline
Host: 2.58.149.41
Date added:2022-04-12 13:34:04 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2022-04-12 13:35:06 UTC to abuse{at}serverion[dot]com)
Takedown time:3 months, 5 days, 3 hours, 40 minutes Bad (down since 2022-07-16 17:15:50 UTC)
Tags:AgentTesla link SnakeKeylogger link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-13n/aexe 2b25983b64ac5f3798cc288cb3b33a1ca891e36cd262cc875067523fb880374en/a SnakeKeylogger
2022-06-13n/aexe 8d8dd56667ebdb071299038d8863053c072e0083a5ac5bbd9f2c2c5fd2587821n/aSnakeKeylogger
2022-06-13n/aexe 2e4e995b85b7e9b9e809c840e9331b1976240bfe94b5edff1641e09026e28349n/aSnakeKeylogger
2022-06-07n/aexe 181fd7b53768803803f237233c783ff3d8182f4e6560d0de84e7e342082d62c3Virustotal results 35.29%SnakeKeylogger
2022-04-12n/aexe caf547df46387b2df2669cc740f45af18c8660a2132542bdd9769466947cc43an/aAgentTesla