URLhaus Database

You are currently viewing the URLhaus database entry for http://190.255.90.152/hold.bat which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3850803
URL: http://190.255.90.152/hold.bat
URL Status:flame Online (spreading malware for 7 days, 18 hours, 15 minutes)
Host: 190.255.90.152
Date added:2026-05-20 16:45:12 UTC
Threat:Malware download Malware download
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-05-20 16:46:20 UTC to admin[dot]internet{at}telecom[dot]com[dot]co)
Tags:exe opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-27hold.batbat 5315f2dcf5f585bbd98b168fd01a01b988fee102a5f0c058a3686fa0e65f2715n/a 
2026-05-21hold.batbat 9428bc7c8a105d40ab25634715d3a5fd22b94952d9ddc4314b572d7f5b653fb2n/a 
2026-05-20hold.batbat 5049677702938359f4318aa41958e24fa066f9d00c18c4369f45729f59dd604bn/a