URLhaus Database

You are currently viewing the URLhaus database entry for http://185.7.214.108/fg.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3459371
URL: http://185.7.214.108/fg.exe
URL Status:Offline
Host: 185.7.214.108
Date added:2025-02-27 05:37:06 UTC
Last online:2025-03-12 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: skocherhan
Abuse complaint sent (?): Yes (2025-02-27 05:38:07 UTC to abuse{at}changway[dot]hk)
Takedown time:13 days, 17 hours, 25 minutes Bad (down since 2025-03-12 23:03:30 UTC)
Tags:AsyncRAT link booking ClickFix FakeCaptcha

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-11n/aexe 873094469e12839ecadbe522ee216289ec9c5ed8342ae9c4f72f5ef9d105c55dn/a AsyncRAT
2025-03-10n/aexe 1e148263823aedb34949cf790a7273eb6ce8bcfe1458cdc90316bce905ffe94aVirustotal results 38.89% AsyncRAT
2025-03-08n/aexe 1be3f3449a4fbe09203249d212c1abe8aead0d3e3ad9c499f0c0e9aaa76f198an/aAsyncRAT
2025-03-07n/aexe 12003cfc75b9d076590abcbe3f960e7b64114f229ace64497d28e260ca01a2b9n/aAsyncRAT
2025-03-05n/aexe c6e052c84a0ed1ad7f463704a5fafffcc845e5744a40eadb84867af10217501dVirustotal results 50.00% AsyncRAT
2025-03-03n/aexe 757af13b416594d65a4c99362a537f13dde2a93b61ec8ba0b939c548b8973186n/a AsyncRAT
2025-02-27n/aexe dcd7f802f5ddf4ce2ffe5bda303c916ae37865c9b10ca97f8fe2bcc7c24f1762Virustotal results 43.06%AsyncRAT