URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.211.92/enterprise/student_s.bin which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3891471
URL: http://158.94.211.92/enterprise/student_s.bin
URL Status:flame Online (spreading malware for 2 days, 8 hours, 14 minutes)
Host: 158.94.211.92
Date added:2026-07-25 11:41:21 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-07-25 11:45:23 UTC to abuse{at}omegatech[dot]sc)
Tags:ClickFix geofenced ua-powershell USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-27student_s.binexe 648a13bf47fe99d31e24166a8648f5a760d64c1b2bb8930e5d6c3fb366ebae22n/a 
2026-07-27student_s.binexe bf738564a068e0f21584032a452101f00496ab4cd341b67022dd15205bfcabe9n/a 
2026-07-27student_s.binexe d4dc3de0cf0991478a151a05400643b160e5df62cd89c02a92b856c4e7602f72n/a 
2026-07-26student_s.binexe a423044b8a13c2f7ed940d101054c4da8c22fc58c09ea5a21d1c17f15d2aae01n/a 
2026-07-26student_s.binexe 8ec5c7c099535ccf85b87f3fd86687fe60528549e49dfdfd9667aaeaf9a6aef7n/a 
2026-07-26student_s.binexe 3ee71c9c5a93e443f418bce6e851afb536925f489b79bf20f141818399ac08bfn/a 
2026-07-25student_s.binexe 34e8319dded36a5134877916a899e5d8ddff62a42fc33c93bd876d548d41559bn/a 
2026-07-25student_s.binexe dfced03763f41d907d67d70117837209a89cbbc53f272d1dff4626fe0237115dn/a