URLhaus Database

You are currently viewing the URLhaus database entry for https://91.92.243.254/Bin/ScreenConnect.ClientSetup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3891948
URL: https://91.92.243.254/Bin/ScreenConnect.ClientSetup.exe
URL Status:flame Online (spreading malware for 1 day, 12 hours, 55 minutes)
Host: 91.92.243.254
Date added:2026-07-26 12:35:29 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2026-07-26 12:36:34 UTC to abuse{at}omegatech[dot]sc)
Tags:91-92-243-254 connectwise exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-28ScreenConnect.ClientSetup.exeexe efd57459495b88f328d81158029ba2a0c130fb9a416b8d76a905397f745e2e08n/a 
2026-07-27ScreenConnect.ClientSetup.exeexe ffb3fad4ba3565bc90a8438cc7dc19564734dcd16e95df234525271b13d7961en/a 
2026-07-27ScreenConnect.ClientSetup.exeexe 242b40d6ea1707dcd0ea8f266a971a847609b4481bcf82a0269fb52620183051n/a 
2026-07-27ScreenConnect.ClientSetup.exeexe 0e1d5c4b61bc46e4f3e944d2ebb4e3cd083a457e7f96cc010df8e4cc40e93945n/a ConnectWise
2026-07-26ScreenConnect.ClientSetup.exeexe 715065b82724398ffaab3d38ebbbd45c23e7dd7f43f059eca9dac81e1e7d00dan/a