URLhaus Database

You are currently viewing the URLhaus database entry for http://2.58.149.41/plugmanzxzx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2239982
URL: http://2.58.149.41/plugmanzxzx.exe
URL Status:Offline
Host: 2.58.149.41
Date added:2022-06-16 05:57:04 UTC
Last online:2022-07-16 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2022-06-16 05:58:06 UTC to abuse{at}serverion[dot]com)
Takedown time:1 month, 0 days, 11 hours, 21 minutes Bad (down since 2022-07-16 17:19:47 UTC)
Tags:exe Formbook link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-01n/aexe 987c22e1dc325066b45d0e996d8c0b4ff9fd3cc96f814e41ae0f80914b6b81e5Virustotal results 70.15% Formbook
2022-06-16n/aexe f9eafc2e0d113c33ff2ef3c080001165cde3e53b379662b35643d4cfaab9e25cVirustotal results 33.82%Formbook