URLhaus Database

You are currently viewing the URLhaus database entry for http://220.85.206.156:8080/AnyDesk_vip.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3612570
URL: http://220.85.206.156:8080/AnyDesk_vip.exe
URL Status:Offline
Host: 220.85.206.156
Date added:2025-08-27 16:45:09 UTC
Last online:2025-09-01 14:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-27 16:46:10 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:4 days, 21 hours, 38 minutes Bad (down since 2025-09-01 14:24:25 UTC)
Tags:meterpreter QuasarRAT link TelegramStealer ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-31AnyDesk_vip.exeexe fcc64b5263eb56df719d9ac9d73d6e7c07f23c5c81de0bcee3ed55d364520bd7Virustotal results 38.89%TelegramStealer
2025-08-30AnyDesk_vip.exeexe 1b2a6f037998a4f5d822bdb2e791e8856d612f868b8d3d4b8b80686b5906a97aVirustotal results 79.17%Meterpreter
2025-08-30AnyDesk_vip.exeexe a4809f733e09ba67704221d86704e3f5f8eb1aeab7a638ec334bb2039b44b1d5Virustotal results 79.17% Meterpreter
2025-08-28AnyDesk_vip.exeexe 11b162c050fe048516e95f77c2b434f7a78eeff1643f15fea8f1879e690420d7Virustotal results 70.83% QuasarRAT
2025-08-27AnyDesk_vip.exeexe 21ea4b39f79a9af056ffc368cc9e78abbddec1838885b00a4d7eaeeb306d8515Virustotal results 70.83%QuasarRAT