URLhaus Database

You are currently viewing the URLhaus database entry for http://192.252.181.93:6635/192.238.178.202.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3558526
URL: http://192.252.181.93:6635/192.238.178.202.dll
URL Status:Offline
Host: 192.252.181.93
Date added:2025-06-05 09:25:42 UTC
Last online:2025-07-20 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-06-05 09:26:07 UTC to mfjp{at}hotmail[dot]com)
Takedown time:1 month, 15 days, 8 hours, 31 minutes Bad (down since 2025-07-20 17:57:21 UTC)
Tags:Gh0stRAT opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-08192.238.178.202.dlldll 1eb84311f1412beed0c71722ef197887af87150b8b1573dc0145d6ff8cf2e0a9n/a Gh0stRAT
2025-06-08192.238.178.202.dlldll b217f5c25ede1b29d280683480ce9c83df1c8a4df37faa359e965fc2fafe4dc5n/a Gh0stRAT
2025-06-07192.238.178.202.dlldll 6e25e8379efbd2a6ea54fd901e3325cf7d1b0c2596bf0aef274f951679104aa8n/a Gh0stRAT
2025-06-06192.238.178.202.dlldll 035e6b2064453bb68a5a21f610be6147c47d9d490eab448097d2d7df57c00843n/a Gh0stRAT
2025-06-06192.238.178.202.dlldll bfc8b1bad52d3c5df91d575fb62ace6f161032d7a34a394048ceabf4f6fcc1c1n/a Gh0stRAT
2025-06-05192.238.178.202.dlldll b642e6abf52baf150f8f06464a4f43fe8c86b984a859a20ba096e2dc950e4bf6Virustotal results 43.66%Gh0stRAT