URLhaus Database

You are currently viewing the URLhaus database entry for http://185.7.214.54/cmd.bat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3443427
URL: http://185.7.214.54/cmd.bat
URL Status:Offline
Host: 185.7.214.54
Date added:2025-02-17 19:36:04 UTC
Last online:2025-03-16 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2025-02-17 19:37:06 UTC to abuse{at}changway[dot]hk)
Takedown time:26 days, 17 hours, 37 minutes Bad (down since 2025-03-16 13:14:30 UTC)
Tags:AsyncRAT link booking ClickFix FakeCaptcha

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-12n/abat 0386d9f6c64c53d4d3b2114feee2089d3d877f0eeb944c80d6a324e44bb199c2n/a AsyncRAT
2025-03-11n/abat 41cd3b036c48b2e10fa3c0a0eb779f5fc8081db62a0bd76c9cd4b9012823d5e5n/a 
2025-03-08n/abat 01e4a72d4384cb95bb63621219152f2c7294a6e4d35ad909613c219092df78a9n/aAsyncRAT
2025-03-05n/abat 89e11b195c89fc104208da51765503cc941c169ef118c8180d268dd1ecf8d096Virustotal results 4.92% AsyncRAT
2025-03-03n/abat 450b752d088f591b1f00292ab2b2e8c411f6a466a873532dca1d51933116c97cn/a AsyncRAT
2025-02-26n/abat ea8ab7529e25f4ea3b96743991ca85954ab37d8e5ca9ff2cb98a35f782a2a4d7n/a AsyncRAT
2025-02-23n/abat f45f0a06114e109da6b45588cb1bf3de0ac259d3c5a7c57b28e65f012471bac3n/a AsyncRAT
2025-02-17n/abat 95bd50b1c849b16159f239b176e9c48d97bc7d841441829ec974997a93cb4c1eVirustotal results 24.59%AsyncRAT