URLhaus Database

You are currently viewing the URLhaus database entry for http://92.255.85.2/b.mp4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3480434
URL: http://92.255.85.2/b.mp4
URL Status:Offline
Host: 92.255.85.2
Date added:2025-03-17 17:36:04 UTC
Last online:2025-04-17 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2025-03-17 17:37:14 UTC to abuse{at}changway[dot]hk)
Takedown time:1 month, 0 days, 20 hours, 2 minutes Bad (down since 2025-04-17 13:39:38 UTC)
Tags:booking ClickFix FakeCaptcha xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-10b.mp4txt 43dbd9ae0369f39d189e3ed0841594c1ac21104f926cc838d9c5bb7333d1afaen/a 
2025-04-10b.mp4txt 0e916a1ae6dc8db3039c2944f7a1addbfcc40b3038e22d115c48c8d5d336b35cn/a 
2025-04-10b.mp4txt 7c4990b5b61dd44a779e5e396317bafae89879001cd6101fa4511b6d134ebb09n/a 
2025-04-10b.mp4txt b7f0eed18cc0a0ce674e3ee8bfcc806cb8ad2d75c85d4563ca2194a7f9aca0den/a 
2025-04-10b.mp4txt 51dea698753a974c49e539607f3d7f23c4eb596fc34f20b420c7ebff36803a92n/a 
2025-04-10b.mp4txt e14b136859d63b53f04f7a2fa6d2c54dd72c215b330b0393249551f83ee12f60n/a 
2025-04-08b.mp4txt cdaab55510a1d8d299f42ad80e4921a838a55197ce6977083c4d34343fbb15e3Virustotal results 11.67% 
2025-04-05b.mp4txt 77dc32f3831f2634674bc8597485459dac56ab8e657363f80cb28d485efd4428n/a 
2025-03-28n/atxt 92e2be3c299857f352d70d0bd9c9e4df836465a378cb8e7ada89dcce9ea34cc8n/a XWorm
2025-03-25n/atxt afc9ff46ede3984d6526148952cd3edc2decb9b325c79a74645d3509bad4e08dn/aXWorm
2025-03-25n/atxt e09d12dda295cf81d7be80344b8122207df774eb66ef70c83aefbde10b383867n/a 
2025-03-25n/atxt d4d5b22050709067ad2c39ff1a60cbcc239c92fb8374c85b5c36d309bb22b768n/a 
2025-03-17n/atxt 955c4a1960a67eec2249a6e0b0587c6b5f65749caa6f414a2c82371953f297d2Virustotal results 4.84%XWorm