URLhaus Database

You are currently viewing the URLhaus database entry for http://92.255.85.2/cmd.bat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3490718
URL: http://92.255.85.2/cmd.bat
URL Status:Offline
Host: 92.255.85.2
Date added:2025-03-26 03:15:03 UTC
Last online:2025-04-11 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2025-03-26 03:56:06 UTC to abuse{at}changway[dot]hk)
Takedown time:16 days, 5 hours, 18 minutes Bad (down since 2025-04-11 09:14:44 UTC)
Tags:AsyncRAT link booking ClickFix dcrat FakeCaptcha xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-10cmd.batbat 6891a8ac137c6c9d36e7236691f9daf2310248c4f165cb4267ec9fd953d797c6n/a XWorm
2025-04-10cmd.batbat 4cb1733f9a7eae6f71bca338349d9d74ee6a61fae8d8bc879c2996c4271c8049Virustotal results 3.28% XWorm
2025-04-10cmd.batbat 61ef8de7208814081d943ce40cf7bd2c1e2f57cd14763353c227b2eeaf212408n/a DCRat
2025-04-10cmd.batbat 0f67d55e96c2d6ba8c9bd34c3fe1ecec6d5fc32dd051741c8b3be00eb692f7ebn/a DCRat
2025-04-10cmd.batbat 04875508db3097e7dca473d6728a4427953cc73f4ea6bdc1cf3743d67c754c70n/a XWorm
2025-04-10cmd.batbat 275dbaa2e20935fa728dd2393adf568ce009b322c96e037f0e8475c582de43afn/a XWorm
2025-04-09cmd.batbat beaee642d46127a62f84497ef859768868cc88c8115329615aebed36a1e242d1n/a XWorm
2025-04-09cmd.batbat 738e047296943d75beb55975eb7cae1e0677124132997ded11bf2db7c15627d9n/a XWorm
2025-04-09cmd.batbat a6132c721760344e63f7902c67ae24fc0a2d16617128e100746c9b0a60f50a61n/a XWorm
2025-04-09cmd.batbat e1c50790a973aa8da62bac806cec3610a44bf09264dfd6513b64e7306e78919bn/a DCRat
2025-04-09cmd.batbat c6f0313bc23a12405b2a09c0a1aa78fbb4dae2714dd6dfc29e7e9e7811365d49n/a XWorm
2025-04-09cmd.batbat 5b754e00e712a0533f4c051d9bd1f9ea577b5809344b29fd2321036c5076f4fbn/a 
2025-04-09cmd.batbat 84aa322934a6e0120ce41317df952349ee08efc935c032e17704168330a8a4a9n/a XWorm
2025-04-09cmd.batbat 0c2769d5cc1cedcfae8e7771da0694e8a157d818a8387d97eea8d10809f86d30n/a XWorm
2025-04-08cmd.batbat 74c1af10f6afc0eaf0c094d79252d3c90f77643e5fb73156f523036a27add71dVirustotal results 1.75% XWorm
2025-04-05cmd.batbat b8dfe557467bc1b3ef79065888ffff8d60088e4a4e648d80b29ffc0c1036af2fn/aAsyncRAT
2025-04-01n/abat 49aefefe6b7dc7f13ef5aeb7002a3c0c77cd1a7dd115eab6472f6f570d902a45n/a XWorm
2025-03-29n/abat 8d23a79b7608c65d0444b2fe8c31d766d57940401cd4904f9594d9bb006ce144n/a XWorm
2025-03-27n/abat 419561b852126f4fb80db3be4487ab8f427c83188869a5f49581dea46037aa55Virustotal results 14.52% 
2025-03-26n/abat 3f7b520f93027782e5db0e094dd1924c78e6562eb6156dd5d001ec4076413be4Virustotal results 20.97%AsyncRAT