URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.41/bluezx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2143640
URL: http://2.58.149.41/bluezx.exe
URL Status:Offline
Host: 2.58.149.41
Date added:2022-04-12 15:16:04 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2022-04-12 15:17:11 UTC to abuse{at}serverion[dot]com)
Takedown time:3 months, 5 days, 1 hours, 58 minutes Bad (down since 2022-07-16 17:15:55 UTC)
Tags:AgentTesla link Formbook link GuLoader link RemcosRAT link xloader

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-13n/aexe 0c1958b0b084f1c315c45a24efb611c0cde0637a68b54687c664c4006640979fn/a AgentTesla
2022-06-13n/aexe ba56b91606f6373797358ed875733e1e0efdfe8c9697cf7a946a77ab3479243en/aAgentTesla
2022-06-12n/aexe 5d5dffaf41046231715971dee9add3f4c62a27c8ace0b4702b709e061a047cdbn/aAgentTesla
2022-06-08n/aexe 5e4433e97269a039b8019f2f66d24dba5e6641d97238ed46803793e1e71d8baan/a RemcosRAT
2022-06-02n/aexe 724822c0f33c87c4b05fc64ff9c817348b4decd6dc2b3836fd51d0a97cf14949n/a GuLoader
2022-04-13n/aexe 2d7820ea980726dc1d5aae214a191c9e17b4e52e82cf389705c49eba07449315n/a 
2022-04-12n/aexe 9c6a6119bc7008246685cb9960fe21969a8bfbbea6659e6e0afa329358c60a50Virustotal results 28.57%Formbook