URLhaus Database

You are currently viewing the URLhaus database entry for http://92.255.57.155/1/2.png which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3332612
URL: http://92.255.57.155/1/2.png
URL Status:Offline
Host: 92.255.57.155
Date added:2024-12-06 07:38:04 UTC
Last online:2025-01-31 00:XX:XX UTC
Threat:Malware download Malware download
Reporter: abus3reports
Abuse complaint sent (?): Yes (2025-01-07 09:30:24 UTC to abuse{at}changway[dot]hk)
Takedown time:23 days, 14 hours, 48 minutes Bad (down since 2025-01-31 00:18:48 UTC)
Tags:Amadey ascii AsyncRAT link ClickFix jpg LummaStealer png powershell ps1 ua-wget xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-22n/aps1 e17cee2ea6241540d5587ba18bc37d66bd7098b348f7e4e652ba614550520ef2n/a AsyncRAT
2025-01-17n/aps1 0484307c062611651ca0dc34554154740e60113ac4c0191c754d2f1af76cb347n/aAmadey
2025-01-17n/aps1 0450eaf83f4ad5806828a12295d467ccc7b0e488248dc5d793951118f04fc523n/aLummaStealer
2025-01-15n/aps1 4917ea65f91b2eac7edad852b8940f2b904d4771f4867dabbf928d79805e9195n/a 
2025-01-14n/aps1 9a42d4f5f028c4f7da66edef20c02bb4c36a1970b1084924bf462057a6aef118Virustotal results 8.20%AsyncRAT
2025-01-13n/aps1 9a3c353b1bd9bff9c0f8a109fd21fe331eb9cb0e86f5c260df52f9eba2f13f72Virustotal results 11.67% XWorm
2025-01-07n/aps1 d6e3fbc61a201ac72495e59f7f2f3967e2ecf11f54675618a17b2ab4986e6f8bVirustotal results 37.70%XWorm