URLhaus Database

You are currently viewing the URLhaus database entry for https://185.255.122.133/uploads/il22.zip which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3203023
URL: https://185.255.122.133/uploads/il22.zip
URL Status:Offline
Host: 185.255.122.133
Date added:2024-10-01 04:50:20 UTC
Last online:2024-10-04 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2024-10-01 04:51:14 UTC to abuse{at}bee-hosted[dot]net)
Takedown time:3 days, 12 hours, 13 minutes Bad (down since 2024-10-04 17:04:45 UTC)
Tags:LummaStealer opendir Stealc zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-10-03n/azip 3f243d4f9e4e60a2e4814fb1f637918aa75836da9717d52e71b2b654135f63c0n/a Stealc
2024-10-03n/azip 6eefd94e128160e5195f64ae9176c14aeaec146a72cad5bf943182b5e0b4dce4Virustotal results 14.75% 
2024-10-01n/azip bc58a6105f2296c2ddc58bc4ffc1c7eca4293ef4e70fe9400303737438f50220Virustotal results 4.69%