URLhaus Database

You are currently viewing the URLhaus database entry for http://185.81.68.147/zx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3349872
URL: http://185.81.68.147/zx.exe
URL Status:Offline
Host: 185.81.68.147
Date added:2024-12-15 08:11:08 UTC
Last online:2025-01-29 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2024-12-15 08:12:12 UTC to abuse{at}changway[dot]hk)
Takedown time:1 month, 15 days, 0 hours, 57 minutes Bad (down since 2025-01-29 09:09:33 UTC)
Tags:clipbanker exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-28n/aexe 92c0f8ac112adab5426d1cc7bcdcbff8b2599067747a87719dc207b0851bf56an/a 
2025-01-27n/aexe 10839f994682ce86483e40729e831320b0f8e3b8115dd616e74cb1f965a06b23Virustotal results 22.22% 
2025-01-24n/aexe 678dd0ca3fe26ad1e5ce60d9bd6494fa0a5dcfb5cede0e063bcc128e0b2c2cden/a 
2025-01-23n/aexe 96dbe6af90b71075f04da218785563eb199c016bc5e97a9a63008bbf9e7ea0a7n/a 
2025-01-22n/aexe e7c2fb7c81184f55ef1ee5e183c426d30547e147b103a7e6554f78f82a9fefa9Virustotal results 22.22% 
2025-01-18n/aexe 807900f83bdbb965da34c897e59c890f82017517d3323d504d322ca14d05bf95Virustotal results 17.91% 
2025-01-17n/aexe 7c99e7feb8c13ac2a9c7961f5b315ac07120b17304b566c540e224e178cbdcfan/a 
2025-01-09n/aexe a39ef65f7ac15a4566b804eea4abf27069618f0770357cf95d2b0d26468b899bVirustotal results 20.83% 
2024-12-30n/aexe ac3f202978c44b410e8e66bfb6276335d43872cce0e9087c07542ca290613bf1Virustotal results 22.22% ClipBanker
2024-12-25n/aexe 0bc67c0fa17dcadfe8a827cb413c090f67b0cb00a14705d95ec37766de241665Virustotal results 22.22%
2024-12-20n/aexe 23cadf34f2779d927959aaaaf079513941accefd4b7b094a57fbbaec1def54a2n/a 
2024-12-15n/aexe 50f3af8a4b14a6e63cdc7817ecb482d7045458b43d786d580b51e8f12d762106Virustotal results 20.83% SVCStealer
2024-12-15n/aexe f40224ca24a6d189791058779eb4c9bab224caa58b00bd787b1ff981d285d5a4Virustotal results 19.44%