URLhaus Database

You are currently viewing the URLhaus database entry for http://185.156.72.2/files/7907190724/H9pAzCD.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3556347
URL: http://185.156.72.2/files/7907190724/H9pAzCD.exe
URL Status:Offline
Host: 185.156.72.2
Date added:2025-06-02 06:58:06 UTC
Last online:2025-06-02 13:XX:XX UTC
Threat:Malware download Malware download
Reporter: c2hunter
Abuse complaint sent (?): Yes (2025-06-02 06:59:07 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:6 hours, 26 minutes Good (down since 2025-06-02 13:25:30 UTC)
Tags:AsyncRAT link c2-monitor-auto dropped-by-amadey QuasarRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-02H9pAzCD.exeexe d7562a39b7b79df30a4ed8e7b05a5e6d65478830f06f1718856ac07fb455e15fVirustotal results 54.29% QuasarRAT
2025-06-02H9pAzCD.exeexe 53e408a848a3cb50ec5c653ca5b99e50c8e5e9cad5e3a38fdd6f70f40da8e290Virustotal results 68.06% AsyncRAT