URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.208.102/zx.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3624967
URL: http://158.94.208.102/zx.exe
URL Status:flame Online (spreading malware for 2 months, 7 days, 6 hours, 28 minutes)
Host: 158.94.208.102
Date added:2025-09-16 07:02:09 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-09-16 07:03:11 UTC to support{at}ipv4[dot]global)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-13zx.exeexe de79aece0cbd492c69474d8c83ca548ffc85e24838c95a298ff4fcd41e5b5795Virustotal results 33.33% 
2025-09-19zx.exeexe 59c6cebfc1b60e8fed91078d412784d3a888034356bd8928a67921d56d222b29Virustotal results 51.43%SVCStealer
2025-09-16zx.exeexe 83160cab62b17b3e27bf30dc7ad8ca99d3892e31d18a9a0c404b832312c4264eVirustotal results 37.50%SVCStealer