URLhaus Database

You are currently viewing the URLhaus database entry for http://45.204.214.219:1230/2.bat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3630367
URL: http://45.204.214.219:1230/2.bat
URL Status:Offline
Host: 45.204.214.219
Date added:2025-09-23 14:20:18 UTC
Last online:2025-10-09 04:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-23 14:21:11 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:15 days, 13 hours, 59 minutes Bad (down since 2025-10-09 04:20:28 UTC)
Tags:CoinMiner

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-292.battxt 9a5be6d0e6449d4d7fb2deb39eff1ca43878969eea0105e5477172d7e354d37bVirustotal results 14.52%CoinMiner
2025-09-232.batunknown 403829e447bf34459fb5082cd5adfb63be3068575d483b52ccbfd2e4cf4a5232Virustotal results 12.90%CoinMiner