URLhaus Database

You are currently viewing the URLhaus database entry for http://92.255.57.112/1/3.png which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3399030
URL: http://92.255.57.112/1/3.png
URL Status:Offline
Host: 92.255.57.112
Date added:2025-01-13 15:27:05 UTC
Last online:2025-01-29 08:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-01-13 15:28:13 UTC to abuse{at}changway[dot]hk)
Takedown time:15 days, 17 hours, 16 minutes Bad (down since 2025-01-29 08:44:54 UTC)
Tags:ascii ClickFix FakeCaptcha LummaStealer powershell ps1

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-01-20n/aps1 d0131ca567b92a13eab0f5630a34a8a8651afbbf2fd9e0a0736ee8ac14db1ebdn/a 
2025-01-17n/aps1 ece6e878006902f7e26b12fa0a440251796983884dc918e524d9fd2185f53269n/aLummaStealer
2025-01-17n/aps1 c67808355bfc8b72ca3656320bf7b4a4c519017e55940a1d7be44bc807d3b103n/a 
2025-01-17n/aps1 e3a416dc21ac6a66f0e7d9c2516d934608a58bb8f07f63b3a593bcde84bf4745n/aLummaStealer
2025-01-15n/aps1 2888104b21bf859339cbfd936fc66d8f048ae04199dc9b84c138b6883ecb6be5n/a LummaStealer
2025-01-14n/aps1 b404ee84e4b5100561bc108c58aedc06cae277cd220067dce59a3c1cc93a3ac1n/aLummaStealer
2025-01-13n/aps1 229385fbe03dd8ab9489ee1f0f4a5916b89be800aa27b7d563b63080211235a9n/aLummaStealer