URLhaus Database

You are currently viewing the URLhaus database entry for http://192.252.181.93:6635/120.89.71.182.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3558528
URL: http://192.252.181.93:6635/120.89.71.182.dll
URL Status:Offline
Host: 192.252.181.93
Date added:2025-06-05 09:25:44 UTC
Last online:2025-07-20 18:XX:XX UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-06-05 09:26:07 UTC to mfjp{at}hotmail[dot]com)
Takedown time:1 month, 15 days, 9 hours, 1 minutes Bad (down since 2025-07-20 18:27:22 UTC)
Tags:Gh0stRAT opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-24120.89.71.182.dlldll e20b8ef13e5e8ca25ad6b05de0886c55be294c832f126b944b72fb1f68557195n/a Gh0stRAT
2025-06-23120.89.71.182.dlldll 05eee5744198ac7b40e9227dc11427e99cbebfd912a431a0a739518ae70605d2n/a Gh0stRAT
2025-06-23120.89.71.182.dlldll 642d2ed7080940ce571b5561ef29a5d8bf006b7e73d1bd281fbf58328d9242acn/a Gh0stRAT
2025-06-22120.89.71.182.dlldll ee296f1508751024f2e119bc6295f49a84feb6c194c6626be083532544d12e52n/a Gh0stRAT
2025-06-05120.89.71.182.dlldll 481f80be12bf59f0f7a813410241e9101d68725e7e5e9dd0caede8709c5a75c9n/aGh0stRAT