URLhaus Database

You are currently viewing the URLhaus database entry for http://92.255.57.221/rh.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3499843
URL: http://92.255.57.221/rh.exe
URL Status:Offline
Host: 92.255.57.221
Date added:2025-04-03 06:36:04 UTC
Last online:2025-04-10 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2025-04-03 06:37:09 UTC to abuse{at}changway[dot]hk)
Takedown time:7 days, 14 hours, 31 minutes Bad (down since 2025-04-10 21:08:17 UTC)
Tags:AsyncRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-09rh.exeexe 77f07c2a7bb9200d75bd17ef369a110cf5366ccae7a06fcf78b8f86c0d972cb3n/a AsyncRAT
2025-04-08rh.exeexe 678f8d7aacd1b070f56534c6b1e107d0a3be70002a2f3b7e6bf5dee8cfa1e54fVirustotal results 27.78% AsyncRAT
2025-04-05rh.exeexe 0f1073c5cacf5009f6097cf771b71ab18e3350fd445935ce72ac1b45fd175291n/aAsyncRAT
2025-04-03rh.exeexe 6735c596466751fda2c3c95c2dc7b6d3f59b68948fa136c5266351426ee32ff4Virustotal results 55.56%AsyncRAT