URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.7.214.54
Firstseen:2025-01-31 06:17:02 UTC
Total malware sites :10
Online malware sites :0 (0%)
Offline Malware sites :10 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-02-23 19:19:06http://185.7.214.54/js.exeOfflineAsyncRAT ext xworm abuse_ch
2025-02-23 19:19:04http://185.7.214.54/d.mp4OfflineAsyncRAT ext xworm abuse_ch
2025-02-23 19:19:04http://185.7.214.54/c.mp4OfflineAsyncRAT ext xworm abuse_ch
2025-02-23 19:18:04http://185.7.214.54/cmd2.batOfflineAsyncRAT ext bat ClickFix fake-cookie xworm abuse_ch
2025-02-17 19:36:05http://185.7.214.54/fg.exeOfflineAsyncRAT ext booking ClickFix FakeCaptcha JAMESWT_MHT
2025-02-17 19:36:04http://185.7.214.54/cmd.batOfflineAsyncRAT ext booking ClickFix FakeCaptcha JAMESWT_MHT
2025-02-13 07:07:03http://185.7.214.54/a.mp4OfflineAsyncRAT ext booking ClickFix facecaptcha xworm JAMESWT_MHT
2025-02-13 07:07:03http://185.7.214.54/b.mp4OfflineAsyncRAT ext booking ClickFix facecaptcha xworm JAMESWT_MHT
2025-01-31 06:17:45http://185.7.214.54/a.jpgOfflinebooking ClickFix FakeCaptcha JAMESWT_MHT
2025-01-31 06:17:18http://185.7.214.54/b.jpgOfflineAsyncRAT ext booking ClickFix FakeCaptcha xworm JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-03-12 23:15:120386d9f6c64c53d4d3b2114feee2089d3d877f0eeb944c80d6a324e44bb199c2bat AsyncRAT
2025-03-11 23:58:4041cd3b036c48b2e10fa3c0a0eb779f5fc8081db62a0bd76c9cd4b9012823d5e5bat  
2025-03-11 23:55:55873094469e12839ecadbe522ee216289ec9c5ed8342ae9c4f72f5ef9d105c55dexe AsyncRAT
2025-03-10 19:56:001e148263823aedb34949cf790a7273eb6ce8bcfe1458cdc90316bce905ffe94aexe AsyncRAT
2025-03-08 15:24:111be3f3449a4fbe09203249d212c1abe8aead0d3e3ad9c499f0c0e9aaa76f198aexeAsyncRAT
2025-03-08 15:00:3501e4a72d4384cb95bb63621219152f2c7294a6e4d35ad909613c219092df78a9batAsyncRAT
2025-03-07 12:11:1312003cfc75b9d076590abcbe3f960e7b64114f229ace64497d28e260ca01a2b9exeAsyncRAT
2025-03-05 17:17:0189e11b195c89fc104208da51765503cc941c169ef118c8180d268dd1ecf8d096bat AsyncRAT
2025-03-05 17:11:277fe172c67413d3bcc1b2ae93b2cbd21eec0aa8a31198828c7dc04a310f9677cctxt AsyncRAT
2025-03-05 16:58:53f560fcadfba19c9b4bb2e063b72661b7d1041d0dba196d6126a625f0f932986ctxt AsyncRAT
2025-03-05 16:43:57c6e052c84a0ed1ad7f463704a5fafffcc845e5744a40eadb84867af10217501dexe AsyncRAT
2025-03-03 13:55:22450b752d088f591b1f00292ab2b2e8c411f6a466a873532dca1d51933116c97cbat AsyncRAT
2025-03-03 13:39:206e1b274d5f98157246546b7de1fef7bdf3a702d1de73f981869551fc5f742dfftxt  
2025-03-03 13:29:347bc88ce6b0ad0a9acbde4ceaa4c9849de407f56038ce7d452a8e507247bb93f7txt  
2025-03-03 12:43:3617c7d4a3d7d090646721f5a1326955c0c4471450bfb76fdeca9b256680da2e71exeAsyncRAT
2025-03-03 12:22:38757af13b416594d65a4c99362a537f13dde2a93b61ec8ba0b939c548b8973186exe AsyncRAT
2025-02-26 22:56:09d382af87b7774ee0cf21b123db976f6f601c312dd9d28693d3496003817b629fexeAsyncRAT
2025-02-26 21:51:59779b035cb60109b6461d41e1241c4dc1231cbc1833eecf31ec3fc6b2d4d7e0f3batAsyncRAT
2025-02-26 21:21:28ea8ab7529e25f4ea3b96743991ca85954ab37d8e5ca9ff2cb98a35f782a2a4d7bat AsyncRAT
2025-02-26 21:19:23dcd7f802f5ddf4ce2ffe5bda303c916ae37865c9b10ca97f8fe2bcc7c24f1762exeAsyncRAT
2025-02-26 18:20:572ea73232203b6895e4e47f09ccac643ba5acb5ccc81d81bc3754a32615259951txt  
2025-02-25 22:41:14d9685a4aef88adbbc61abc68541fe46c72041aae3a0c78ad4d1a2d950922f0c9exe AsyncRAT
2025-02-25 21:27:023f943c7f3d08ba37ee8ae88b1fce4453cb089600843f23e9455ca1503e38b641exe AsyncRAT
2025-02-24 19:54:3049948536265d2718f82f82a475b239cbd0bd7987adfdc00a75210ac4754ebca9exe AsyncRAT
2025-02-24 19:02:2094a71f56783e5a97691711ff7c2f2a17a507925c535e773ed81b1faebab478ecexeAsyncRAT
2025-02-24 18:30:301e9d019c2706216fceb50fa55016fc987fdd1cee126206fc6b75c657c6f287f3bat AsyncRAT
2025-02-23 20:54:27b9557e259b9c21a957046c85995fd377a73c6901a32214abaac256e03c6fced1txtAsyncRAT
2025-02-23 20:45:123455110c6af3b5596ce2eee804f9c308e78cf28d1e9b59336beae2b4d0f274c5batAsyncRAT
2025-02-23 20:31:315388c97788668e94c859cdb59688c07c01382ee28a86b501506a5a7f387b392etxtAsyncRAT
2025-02-23 20:27:037fa6c8eccdd800125aa09dad0ced1c52f01ecf33c2a5d5edcf3c902b806af1d8txt  
2025-02-23 19:54:07f45f0a06114e109da6b45588cb1bf3de0ac259d3c5a7c57b28e65f012471bac3bat AsyncRAT
2025-02-23 19:19:066ccf420404626efbb29b50619b7b942ef008a84688642ff091ebf871b8db8247exeXWorm
2025-02-23 19:19:041dd93b1564e0c685a499ae78b60382c971ccf7a25e7239bae1fee36eeb8c54f3txtXWorm
2025-02-23 19:19:04533eb308de57813df0c9cb78155407cf3225ad776dd64b02b33a6d4e3370f1eftxtXWorm
2025-02-23 19:18:04607aa94accb5f1e2aac06e7c5dd7dedc9202f16e0a8c5e7c2cba84141782b1fdbatAsyncRAT
2025-02-23 19:13:3165d6bf2bb7c4a2c3116980fac1e3b5b9a7e0e5f4ed2555a70943045fc694c4datxt  
2025-02-21 19:12:5013e420f9f393dfd6380a6d470fe128e0ffb8f5e6414c63917044e9fec8b42a44exe AsyncRAT
2025-02-19 22:06:5616ab5e36bca74a0d289c9a3b5700772c15c01548fa98ef45dd098c11d110198fexeAsyncRAT
2025-02-17 19:44:240a5ba202d902f6015bc2e398864b6b4cdd9db8dac88caebf2c9c5e8d8c029a13txt AsyncRAT
2025-02-17 19:36:0507253a1e6616775fcf3fa678512f2e18c0b557b043127b14b3446aa352e99d49exeAsyncRAT
2025-02-17 19:36:0495bd50b1c849b16159f239b176e9c48d97bc7d841441829ec974997a93cb4c1ebatAsyncRAT
2025-02-17 19:15:45e43399dac848eb1744215553c6e5ec32127af5974c9482f970bfaea0fe60d6a4txtAsyncRAT
2025-02-13 07:07:03a236041466bb178baae9a3e7bba8f50e4dd89d3c0a12e9d8eb6fa8c088b63381txtAsyncRAT
2025-02-13 07:07:0380a21952b87d83eb419768268b334364ecab48dbb9cbe55b967ba9636e512cabtxtAsyncRAT
2025-02-05 16:19:295f0a5c454edbedfb58a952a000cae09e1c910a2813bc3e851313d9340633252eps1SharpHide
2025-02-01 14:26:42c88a4bfb076081f21b6b49e709d8a81e2fbcba350935da64d695329650c9a476ps1SharpHide
2025-02-01 14:11:4914b786f8300fee24d2481222f7e4bbc5785b444e8404e31f649b64f364392cfeps1XWorm
2025-01-31 09:12:597600ab4fd6fba0c38358897795445bef990a56bd604671b09a93c7763f8c2205ps1SharpHide
2025-01-31 06:17:18c901dcc4cd20911a0d9d7f3f8ce6118d111eaf274b375770d14bde02644f2411ps1AsyncRAT