URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.41/plugmanzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2229281
URL: http://2.58.149.41/plugmanzx.exe
URL Status:Offline
Host: 2.58.149.41
Date added:2022-06-08 02:47:05 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-06-08 02:48:06 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 8 days, 14 hours, 26 minutes Bad (down since 2022-07-16 17:14:50 UTC)
Tags:32 exe Formbook link NanoCore link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-01n/aexe c085bc0fdaa618fb6d1d8b6db3de60b533075613d47779c18cd7af6ef9f87101Virustotal results 52.31% Formbook
2022-06-15n/aexe f9eafc2e0d113c33ff2ef3c080001165cde3e53b379662b35643d4cfaab9e25cn/aFormbook
2022-06-15n/aexe ff39e3b670a02fbdb1f24e9cf9f85a9eeb1f3a00e75f0dbac83a18b1fcdcd3f5Virustotal results 33.82% 
2022-06-14n/aexe e79387b4f694e147f4a6cf4b181b650c8b1da5f4ecc47799f3964e830ac11bb6n/a 
2022-06-14n/aexe f55b3a4dc7510439401745fdb3330df93d61b35be96adc52db3ac3a23f3d93c1n/a 
2022-06-13n/aexe 96ad797d56d4f371624479d61fb8d760a745dd378d166b3ced7fa8146231f4e8n/a 
2022-06-13n/aexe 592b026b4d94568a2e9b9ee96b6628bc004ab94165b1b6c8b00e0693b5c99992n/a 
2022-06-13n/aexe 0b6c6f381fa19e3c3d2a4dbd80adcc7724f23c57e72e0add9a7aec9dfcbe327cn/aNanoCore
2022-06-12n/aexe d466cf23cd8845ae7772574dea01b4acbb0c14e4f737b04a57df38da8b0ae321n/a Formbook
2022-06-11n/aexe fc8d47ab825611a1fcd4f5e6d7d3f5f82873a220c702aeda8d2072bbd1d522ban/a 
2022-06-10n/aexe 32adafbb2dde31b58c581fba4529b64fc63bf60edd5208ad674e52ccee17cf92n/a 
2022-06-09n/aexe ea686eef3f3467e0305477cf1759632fd744556b362b6571ec70e961fe9cd4dcn/a 
2022-06-09n/aexe 67c422f6e70ab7f126b8b7eee480d4a0577015215359199b8e090aa855c0f199n/a 
2022-06-09n/aexe faea34e7c75efd701ec53a1767b8719725c91430164d28ec7853543be56acf41n/aFormbook
2022-06-08n/aexe e9a379a7a0bec2e05abc9e95b41473ea999b8faa57f4e4aab6ae27eb9a35659cn/a 
2022-06-08n/aexe 8425a88a6f37dd87c2aac358fe3a248490b56bf4f7728620805f53bc166ceeben/a 
2022-06-08n/aexe c890f6556786c0c3bd8f2620c01139ae4bcdf0bb12e9b4328ef9dd721f0bed03n/a 
2022-06-08n/aexe 9530780503c903e1d83738e19e754c3756e067612adddcea2f64c25749b6a838Virustotal results 33.33%NanoCore