URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.41/samizx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2229884
URL: http://2.58.149.41/samizx.exe
URL Status:Offline
Host: 2.58.149.41
Date added:2022-06-08 14:19:03 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: James_inthe_box
Abuse complaint sent (?): Yes (2022-06-08 14:20:07 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 8 days, 2 hours, 55 minutes Bad (down since 2022-07-16 17:16:02 UTC)
Tags:Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-01n/aexe 2c2644a923b6945bac3aa4698e16832c6b66634776f3fe7e7cde16d1df93858bn/a Formbook
2022-06-16n/aexe bd160397bf50b0145ca8a7c72841a79d9280e60d1a005535e06ccec368f70122n/a 
2022-06-14n/aexe 69af526dae44e6d6cd6c83d443d2129c948e7c46d099d89f48a4bbecbab61cfdn/aFormbook
2022-06-14n/aexe 946ef46761c09fb06c70a1109c82230230d148137405a6ca99d5149a265bdc5bn/aFormbook
2022-06-13n/aexe e2cad68c34f33a78a94919fee5c51d1b100f4f74fb8a0fac042f59c4ff541d94n/a 
2022-06-13n/aexe ddd28f7f398476788cb6303c4aaf8fad5a316e68e17b57836ef57a089ce41740n/aFormbook
2022-06-12n/aexe 05a83db86588f92b1f68afd472b57e4e44c04e668b152bc8e483a4f917f1a27an/a 
2022-06-11n/aexe f44a2bd961c51934b940452694125fbce0f6a0a10b3e60ca95dee11f813e1a7fn/a Formbook
2022-06-10n/aexe 08fa4c089f40cee59514d946f60e0da1dc3898f1b946a9037c0d012e53e42ea1n/a Formbook
2022-06-09n/aexe 3c29ade6ea5d05011a90fdfe39a3eb0a48738ffbec0ceb7a1bf2e4f321dfa557n/aFormbook
2022-06-08n/aexe e322a26ae84aa34c37b31d14fca0e535fa594d570765d93d3542d428e31da0c3Virustotal results 32.35%Formbook