URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 107.175.113.252
Firstseen:2024-08-23 05:58:04 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-08-23 05:58:09 107.175.113.252107-175-113-252-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-09-25 06:16:08http://107.175.113.252/171/audiodg.exeOfflineexe rat RemcosRAT ext abuse_ch
2024-09-25 06:16:06http://107.175.113.252/xampp/mn/IEnetwbookcooki...Offlinehta rat RemcosRAT ext abuse_ch
2024-08-23 05:58:10http://107.175.113.252/145/nbj/nicebabywithcute...Offlinedoc rat RemcosRAT ext abuse_ch
2024-08-23 05:58:09http://107.175.113.252/145/goodpicturewithgoodb...Offlinerat RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-09-25 06:16:08ff67f46cb0b8c93cc038c969376a92b04ab3809b0efd52f99bdfbbd9a991cc87exeRemcosRAT
2024-09-25 06:16:063dab14859030e20708a39df701feb49b3b33097a3b1178d1801be40746c43232htaRemcosRAT
2024-08-23 05:58:06d5c9ffe0379eaf8d85d979a912bb12708eb3114905c5f4019257fc64c007af41rtfRemcosRAT