URLhaus Database

You are currently viewing the URLhaus database entry for http://185.7.214.54/js.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3450181
URL: http://185.7.214.54/js.exe
URL Status:Offline
Host: 185.7.214.54
Date added:2025-02-23 19:19:06 UTC
Last online:2025-03-16 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-02-23 19:20:05 UTC to abuse{at}changway[dot]hk)
Takedown time:20 days, 17 hours, 54 minutes Bad (down since 2025-03-16 13:14:29 UTC)
Tags:AsyncRAT link xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-03n/aexe 17c7d4a3d7d090646721f5a1326955c0c4471450bfb76fdeca9b256680da2e71n/aAsyncRAT
2025-02-26n/aexe d382af87b7774ee0cf21b123db976f6f601c312dd9d28693d3496003817b629fVirustotal results 36.11%AsyncRAT
2025-02-25n/aexe d9685a4aef88adbbc61abc68541fe46c72041aae3a0c78ad4d1a2d950922f0c9n/a AsyncRAT
2025-02-24n/aexe 94a71f56783e5a97691711ff7c2f2a17a507925c535e773ed81b1faebab478ecn/aAsyncRAT
2025-02-23n/aexe 6ccf420404626efbb29b50619b7b942ef008a84688642ff091ebf871b8db8247Virustotal results 47.37%XWorm