URLhaus Database

You are currently viewing the URLhaus database entry for http://185.7.214.108/cmd.bat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3459368
URL: http://185.7.214.108/cmd.bat
URL Status:Offline
Host: 185.7.214.108
Date added:2025-02-27 05:37:05 UTC
Last online:2025-03-16 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: skocherhan
Abuse complaint sent (?): Yes (2025-02-27 05:38:07 UTC to abuse{at}changway[dot]hk)
Takedown time:17 days, 7 hours, 19 minutes Bad (down since 2025-03-16 12:57:22 UTC)
Tags:AsyncRAT link bat booking ClickFix fake-cookie FakeCaptcha xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-12n/abat 0386d9f6c64c53d4d3b2114feee2089d3d877f0eeb944c80d6a324e44bb199c2n/a AsyncRAT
2025-03-12n/abat be204e48359d6df7c595f833165aa3a0b846b56de5e1ea87e9066a798cf573f5n/a AsyncRAT
2025-03-12n/abat 41cd3b036c48b2e10fa3c0a0eb779f5fc8081db62a0bd76c9cd4b9012823d5e5n/a 
2025-03-08n/abat 01e4a72d4384cb95bb63621219152f2c7294a6e4d35ad909613c219092df78a9n/aAsyncRAT
2025-03-05n/abat 89e11b195c89fc104208da51765503cc941c169ef118c8180d268dd1ecf8d096Virustotal results 4.92% AsyncRAT
2025-03-03n/abat 450b752d088f591b1f00292ab2b2e8c411f6a466a873532dca1d51933116c97cn/a AsyncRAT
2025-02-27n/abat ea8ab7529e25f4ea3b96743991ca85954ab37d8e5ca9ff2cb98a35f782a2a4d7n/a AsyncRAT