URLhaus Database

You are currently viewing the URLhaus database entry for http://185.7.214.54/fg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3443428
URL: http://185.7.214.54/fg.exe
URL Status:Offline
Host: 185.7.214.54
Date added:2025-02-17 19:36:05 UTC
Last online:2025-03-12 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2025-02-17 19:37:06 UTC to abuse{at}changway[dot]hk)
Takedown time:23 days, 3 hours, 20 minutes Bad (down since 2025-03-12 22:57:59 UTC)
Tags:AsyncRAT link booking ClickFix FakeCaptcha

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-11n/aexe 873094469e12839ecadbe522ee216289ec9c5ed8342ae9c4f72f5ef9d105c55dVirustotal results 41.10% AsyncRAT
2025-03-10n/aexe 1e148263823aedb34949cf790a7273eb6ce8bcfe1458cdc90316bce905ffe94aVirustotal results 38.89% AsyncRAT
2025-03-08n/aexe 1be3f3449a4fbe09203249d212c1abe8aead0d3e3ad9c499f0c0e9aaa76f198an/aAsyncRAT
2025-03-07n/aexe 12003cfc75b9d076590abcbe3f960e7b64114f229ace64497d28e260ca01a2b9n/aAsyncRAT
2025-03-05n/aexe c6e052c84a0ed1ad7f463704a5fafffcc845e5744a40eadb84867af10217501dVirustotal results 36.11% AsyncRAT
2025-03-03n/aexe 757af13b416594d65a4c99362a537f13dde2a93b61ec8ba0b939c548b8973186n/a AsyncRAT
2025-02-26n/aexe dcd7f802f5ddf4ce2ffe5bda303c916ae37865c9b10ca97f8fe2bcc7c24f1762n/aAsyncRAT
2025-02-25n/aexe 3f943c7f3d08ba37ee8ae88b1fce4453cb089600843f23e9455ca1503e38b641n/a AsyncRAT
2025-02-24n/aexe 49948536265d2718f82f82a475b239cbd0bd7987adfdc00a75210ac4754ebca9Virustotal results 44.44% AsyncRAT
2025-02-21n/aexe 13e420f9f393dfd6380a6d470fe128e0ffb8f5e6414c63917044e9fec8b42a44n/a AsyncRAT
2025-02-19n/aexe 16ab5e36bca74a0d289c9a3b5700772c15c01548fa98ef45dd098c11d110198fVirustotal results 44.44%AsyncRAT
2025-02-17n/aexe 07253a1e6616775fcf3fa678512f2e18c0b557b043127b14b3446aa352e99d49Virustotal results 36.62%AsyncRAT