URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 107.173.47.164
Firstseen:2025-05-16 19:11:03 UTC
Total malware sites :30
Online malware sites :0 (0%)
Offline Malware sites :30 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-05-16 19:11:05 107.173.47.164107-173-47-164-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-05-20 07:19:03http://107.173.47.164/960/seeingwithfutrwewillr...Offlinerat RemcosRAT ext abuse_ch
2025-05-19 17:26:06https://107.173.47.164/970/botharefgoodformajor...Offlineascii censys Encoded RemcosRAT ext rev-base64-loader NDA0E
2025-05-19 17:26:06https://107.173.47.164/800/bestkingsgivenmegood...Offlinecensys vbs NDA0E
2025-05-19 17:26:06https://107.173.47.164/900/weneedbetterperofman...Offlineascii censys Encoded jalapeno rev-base64-loader NDA0E
2025-05-19 17:26:05https://107.173.47.164/800/bestkingsgivenmegood...Offlineascii censys Encoded jalapeno rev-base64-loader NDA0E
2025-05-19 17:26:04https://107.173.47.164/960/seeingwithfutrwewill...Offlinecensys vbe NDA0E
2025-05-19 17:26:04https://107.173.47.164/950/withnodenczgirlfrien...Offlinecensys vbe NDA0E
2025-05-19 17:26:03https://107.173.47.164/970/botharefgoodformajor...Offlinecensys vbe NDA0E
2025-05-19 17:26:03https://107.173.47.164/900/weneedbetterperofman...Offlinecensys vbs NDA0E
2025-05-19 17:26:03https://107.173.47.164/xampp/kgc/verygoodmornin...Offlinecensys vbe NDA0E
2025-05-19 17:25:07https://107.173.47.164/970/nko/botharefgoodform...Offlinecensys hta RemcosRAT ext NDA0E
2025-05-19 17:25:07http://107.173.47.164/970/nko/botharefgoodforma...Offlinecensys hta RemcosRAT ext NDA0E
2025-05-19 17:25:07https://107.173.47.164/800/bnm/bestkingsgivenme...Offlinecensys doc RemcosRAT ext NDA0E
2025-05-19 17:25:06https://107.173.47.164/900/wcg/weneedbetterpero...Offlinecensys doc RemcosRAT ext NDA0E
2025-05-19 17:25:06https://107.173.47.164/950/wec/withnodenczgirlf...Offlinecensys doc RemcosRAT ext NDA0E
2025-05-19 17:25:06https://107.173.47.164/xampp/kgc/kgn/verygoodmo...Offlinecensys hta RemcosRAT ext NDA0E
2025-05-19 17:22:11http://107.173.47.164/970/botharefgoodformajorw...Offlineascii censys Encoded RemcosRAT ext rev-base64-loader NDA0E
2025-05-19 17:22:10http://107.173.47.164/800/bestkingsgivenmegoodg...Offlineascii censys Encoded jalapeno rev-base64-loader NDA0E
2025-05-19 17:22:09http://107.173.47.164/900/weneedbetterperofmanc...Offlineascii censys Encoded jalapeno rev-base64-loader NDA0E
2025-05-19 17:22:06http://107.173.47.164/960/seeingwithfutrwewillr...Offlinecensys vbe NDA0E
2025-05-19 17:22:05http://107.173.47.164/970/botharefgoodformajorw...Offlinecensys vbe NDA0E
2025-05-19 17:22:03http://107.173.47.164/800/bestkingsgivenmegoodg...Offlinecensys vbs NDA0E
2025-05-19 17:22:03http://107.173.47.164/900/weneedbetterperofmanc...Offlinecensys vbs NDA0E
2025-05-19 17:22:03http://107.173.47.164/950/withnodenczgirlfriend...Offlinecensys vbe NDA0E
2025-05-19 17:21:06http://107.173.47.164/900/wcg/weneedbetterperof...Offlinecensys doc RemcosRAT ext NDA0E
2025-05-19 17:21:06http://107.173.47.164/800/bnm/bestkingsgivenmeg...Offlinecensys doc RemcosRAT ext NDA0E
2025-05-19 17:21:06http://107.173.47.164/950/wec/withnodenczgirlfr...Offlinecensys doc RemcosRAT ext NDA0E
2025-05-16 19:37:05http://107.173.47.164/xampp/kgc/verygoodmorning...Offlineascii Encoded rat RemcosRAT ext rev-base64-loader abuse_ch
2025-05-16 19:37:03http://107.173.47.164/xampp/kgc/verygoodmorning...Offlinerat RemcosRAT ext abuse_ch
2025-05-16 19:11:05http://107.173.47.164/xampp/kgc/kgn/verygoodmor...Offlinehta RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-05-19 17:26:06b7c983760330e601d3b2ce2351883f0b6c6acbc4bcaaf730d9a4daf9cff41ef5txt RemcosRAT
2025-05-19 17:26:0672550b35ad6fec5040f8252a0883decdfed9e5654b6e36cc47b765b91e0ad7c3txt Jalapeno
2025-05-19 17:26:0572550b35ad6fec5040f8252a0883decdfed9e5654b6e36cc47b765b91e0ad7c3txt Jalapeno
2025-05-19 17:26:04d9146a6642b935502050ac7e806fcad577f9de4ca1ed271b4e1c65cfa65a31deunknown 
2025-05-19 17:25:077669571ab106028c768ca287ed8d40f62f74a8620a1814e00906bf5019648b24htaRemcosRAT
2025-05-19 17:25:077669571ab106028c768ca287ed8d40f62f74a8620a1814e00906bf5019648b24htaRemcosRAT
2025-05-19 17:25:07d27160038bbf4bd911730c5811a5ef2fef1dc93d1254517b5c0de4c8125dadd8rtfRemcosRAT
2025-05-19 17:25:069b644fcaed6386b1256248258a1946248d29e72949ba28bdc279f5f326f81a3bhtaRemcosRAT
2025-05-19 17:25:0679f087b11cd793f4f98c53a7d22a8fcddc55f3dac9df131c5c4bf8617ff47593rtfRemcosRAT
2025-05-19 17:25:06d030fe317f1fc1a09b33063b42d68a8d81d07688bd918e7e30c1b55a5ade4b62rtfRemcosRAT
2025-05-19 17:22:11b7c983760330e601d3b2ce2351883f0b6c6acbc4bcaaf730d9a4daf9cff41ef5txt RemcosRAT
2025-05-19 17:22:1072550b35ad6fec5040f8252a0883decdfed9e5654b6e36cc47b765b91e0ad7c3txt Jalapeno
2025-05-19 17:22:0972550b35ad6fec5040f8252a0883decdfed9e5654b6e36cc47b765b91e0ad7c3txt Jalapeno
2025-05-19 17:22:06d9146a6642b935502050ac7e806fcad577f9de4ca1ed271b4e1c65cfa65a31deunknown 
2025-05-19 17:21:06d030fe317f1fc1a09b33063b42d68a8d81d07688bd918e7e30c1b55a5ade4b62rtfRemcosRAT
2025-05-19 17:21:06d27160038bbf4bd911730c5811a5ef2fef1dc93d1254517b5c0de4c8125dadd8rtfRemcosRAT
2025-05-19 17:21:0679f087b11cd793f4f98c53a7d22a8fcddc55f3dac9df131c5c4bf8617ff47593rtfRemcosRAT
2025-05-17 17:06:599b644fcaed6386b1256248258a1946248d29e72949ba28bdc279f5f326f81a3bhtaRemcosRAT
2025-05-16 19:37:05e2d43327510827a15a837f0f18ff9d7b41c9435d2ee32382f73afbc21d25021ctxt RemcosRAT
2025-05-16 19:11:0538e712338e7f7c03ea06226651766329e90eb80ac9f7eaafa9b2792fd43bab78htaRemcosRAT