URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.241.59/bizy.x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3720814
URL: http://91.92.241.59/bizy.x86
URL Status:flame Online (spreading malware for 2 months, 0 days, 19 hours, 6 minutes)
Host: 91.92.241.59
Date added:2025-11-30 02:00:19 UTC
Threat:Malware download Malware download
Reporter: botnetkiller
Abuse complaint sent (?): Yes (2025-11-30 02:01:14 UTC to abuse{at}lanedo[dot]net)
Tags:elf geofenced ua-wget USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-29n/aelf 85b2c2053d59f8ec783289e633b038ab672bc8d7e02406530411ca8742bc143en/a
2026-01-06n/aelf 9659695456f64b73d0ed7696cd4a73807ee4ce2c0fa6e350be759d324fc00a7an/a
2026-01-02n/aelf eafee07cecd7f87f4d02c5cb6079a4a5689ebc494b9c28d7a1dc369348e6a4bdn/a
2025-12-31n/aelf a611b179d3b97ec0daba5252f9cef3afb18157b661a69f0d39a0b7f749708ca4n/a
2025-12-30n/aelf 51e396f4557ed6f8b2253fc270eed51055418a4993ab60e276ff9f62a0f6b4cfn/a
2025-11-30n/aelf da3e18e3ef495fb7983a2357550d64833b22ab3c4d93d17ac62b7a5d76adee86Virustotal results 31.75%