URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.208.7/files/8167064937/DAIs3ZV.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3797366
URL: http://158.94.208.7/files/8167064937/DAIs3ZV.exe
URL Status:flame Online (spreading malware for 2 days, 13 hours, 47 minutes)
Host: 158.94.208.7
Date added:2026-03-16 19:13:08 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-03-16 19:14:13 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-amadey fbf543 WallStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-19DAIs3ZV.exeexe e70dcfdb5aec8b8ace064687de940a003315fae5b93847010b799247f7b910ffn/a WallStealer
2026-03-18DAIs3ZV.exeexe ebf11a03228f7bb5dae7f7b516aac97eab2e25ff04905c6d660b0d11b6a57934n/aWallStealer
2026-03-17DAIs3ZV.exeexe 6d33f632c9b59f6a6839ee32cb613f5409aa7007785358e12c3e4f1c11f17fa3n/aWallStealer
2026-03-17DAIs3ZV.exeexe 799adfb611860dc8cdfa7301953d68b7f54d2f2c6cbfcda80638cdf63d1fd1afn/aWallStealer
2026-03-16DAIs3ZV.exeexe db640712b6bc2ee316ec5e13cf2de147abf1155dcf4bb2d76760752a01b00facn/aWallStealer