URLhaus Database

You are currently viewing the URLhaus database entry for http://92.255.85.2/a.mp4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3480432
URL: http://92.255.85.2/a.mp4
URL Status:Offline
Host: 92.255.85.2
Date added:2025-03-17 17:36:02 UTC
Last online:2025-04-17 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2025-03-26 07:36:07 UTC to abuse{at}changway[dot]hk)
Takedown time:22 days, 5 hours, 30 minutes Bad (down since 2025-04-17 13:06:56 UTC)
Tags:AsyncRAT link booking ClickFix FakeCaptcha xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-10a.mp4txt 8870f3629a36cd97c682fd373d9db09fbf40cb0fc3b745acd666f7c287659ddcn/a 
2025-04-10a.mp4txt 1f02a0d4cc0958f69cfc452f54bfac491e489ee33666186b8014dc3561ac30b0n/a 
2025-04-10a.mp4txt ba756feddc5f20f1c0e275925c06a50b1c02cc4e84617d557d854e1898cd8cdcn/a 
2025-04-10a.mp4txt b9e0094aa2f936a372de2428f5e0544dca37222e4458f3cf441b393861ba3460n/a 
2025-04-10a.mp4txt a344f2c0f8d8d7538b6e6e28ff7dee22211d021c4f2685285d296e64ab9b603bn/a 
2025-04-08a.mp4txt ce3ee6dfb8b4a9a5947f8fe21d72319b50a65523215f86e26f59d4524fa7ed98n/a 
2025-04-08a.mp4txt dc4f1378ab63c77b6dd9d1ea58c055f5ee79fb7a4b31fc370889f30a707d2642n/a 
2025-04-06a.mp4txt d208e1e874110983a74ca484f4b3e44fbfd0685215ad59b1ccc70da2a09b24c6n/a 
2025-03-27n/atxt 0135b1aed1e0ef32dc906a7d058e6f208c2b08bfd9567f3e6e1acd759439cf35n/a XWorm
2025-03-26n/atxt b24c140f1ab6876e230826f829468f77c4f72316ee71477fe51c4c42906dd3efVirustotal results 4.84%AsyncRAT