URLhaus Database

You are currently viewing the URLhaus database entry for http://185.157.160.147:4444/aba.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1602512
URL: http://185.157.160.147:4444/aba.exe
URL Status:Offline
Host: 185.157.160.147
Date added:2021-09-08 12:49:28 UTC
Last online:2021-09-09 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-08 12:50:09 UTC to abuse{at}ovpn[dot]com)
Takedown time:1 day, 9 hours, 59 minutes Poor (down since 2021-09-09 22:49:48 UTC)
Tags:32 AsyncRAT link bitrat link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-08n/aexe a2e507885670e4e696c1c7815fe33a0173f03c8f2d109cc9ceb723d347cd8e65n/aAsyncRAT
2021-09-08n/aexe 1d49c795e503a5c5c57885ae435b84f2d00a342ea122110a075b4df7b3c4ddd2Virustotal results 17.65%BitRAT
2021-09-08n/aexe fe667229b0d0f7e10a60bae77865d8d311bdd731465d7ddfae610610def853fbVirustotal results 28.12%BitRAT
2021-09-08n/aexe b14f09bfe66195abe644a6ba5463bdcdf29ebd04922f83000e7779a08e0d9a02Virustotal results 39.13%BitRAT