URLhaus Database

You are currently viewing the URLhaus database entry for http://92.255.57.221/yr.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3459616
URL: http://92.255.57.221/yr.exe
URL Status:Offline
Host: 92.255.57.221
Date added:2025-02-27 10:59:05 UTC
Last online:2025-03-12 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2025-02-27 11:00:08 UTC to abuse{at}changway[dot]hk)
Takedown time:13 days, 10 hours, 37 minutes Bad (down since 2025-03-12 21:37:52 UTC)
Tags:AsyncRAT link booking ClickFix FakeCaptcha xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-11n/aexe a91b2c3532dd53d77f321e0bcbd2e5bafb4ac4311d7d632dfd28eb286e6eb7ccn/a AsyncRAT
2025-03-10n/aexe cf8aa638e3982b6f37c4a3070381663b65c0ebca89c394c06728d35ae7239a3en/aAsyncRAT
2025-03-08n/aexe 01565baa85ddb4b7034c620d9428024b43ae2375b8311e84aa7f06b91cc2c414n/aXWorm
2025-03-07n/aexe b801cb04e76aac8532e1121720c73b171601389f9f7ea7b1d1bcbe64b547606en/a AsyncRAT
2025-03-05n/aexe 23032b40ae8e426a584fa384f678628ab575f90c21c609cb989d40a45709dfe0n/a AsyncRAT
2025-03-02n/aexe 713a9ec5fe2a81686942a159c168027da5910e72fd52d914cf8e6fc0a2cdb0e5n/a AsyncRAT
2025-02-28n/aexe df98433d950c244f22d47ef792389de3009b61d4caced074d85eefe08fe9a6baVirustotal results 40.85% AsyncRAT
2025-02-27n/aexe 4d2e3c53adb98c3e19ca07a06a3a30618c3c232f38687d2d33d346536d168d54Virustotal results 46.48%AsyncRAT