http://158.94.211.162/4.exe

Classification: Malicious

http://158.94.211.162/4.exe is a malicious URL. Linked to Zeroaccess malware. Reported by 1 threat source, last seen 2026-03-19.

Current activity

  • Offline — no longer resolving. Last online 2026-04-14 14:56:44.
  • Malware distribution — This indicator is distributing malware.

MITRE ATT&CK associations

Malware families: ZEROACCESS (S0027)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Zeroaccess Maltiverse Threat Observatory 2026-03-17 23:31:33 2026-03-19 22:31:17 country_code:za industry:government-and-public-sector S0027 Zeroaccess

URL information

Direct IP
158.94.211.162 — this URL points straight to an IP address, a strong indicator of malicious use.
SHA-256
3e5407406f721dff6ad7430ff50c2002870b6792bd8d79fc01d0b6f6fe952443
First indexed
2026-03-18 21:42:32
Last updated
2026-04-14 14:56:44
Last online
2026-04-14 14:56:44