URLhaus Database

You are currently viewing the URLhaus database entry for http://91.92.243.29/4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3780852
URL: http://91.92.243.29/4
URL Status:flame Online (spreading malware for 9 days, 21 hours, 40 minutes)
Host: 91.92.243.29
Date added:2026-02-18 22:03:06 UTC
Threat:Malware download Malware download
Reporter: Bitsight
Abuse complaint sent (?): Yes (2026-02-18 22:04:10 UTC to abuse{at}omegatech[dot]sc)
Tags:dropped-by-Phorpiex

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-274unknown 6edd72592c734ee3d7e7f04069e86e2625f6ba4b727d9bcb99969220b3571dfdn/a 
2026-02-234unknown b0553c7c39c6da09013816228024dc3bf0cf51ecc1b1ce7c704f23872d28978dn/a 
2026-02-194unknown a3a3c5ae5ab34827ad0fdb43b93e7496d8d0163f208573e5cee50a13a5d64fe1n/a 
2026-02-184unknown 89e9074958575d1a516db78a58f5f9283fc55adbc9b571ee7c0492bd59b8d6c1n/a