🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 154.12.118.41
Firstseen:2026-09-29 08:20:16 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2026-09-29 08:20:24 154.12.118.41Not listedAS26832 RICAWEBSERVICES- CAyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2026-09-29 12:40:14http://154.12.118.41/58/mdpjioA.txtOfflinerat RemcosRAT ext rev-base64-loader abuse_ch
2026-09-29 08:20:24http://154.12.118.41/58/image_03949595959.jpg.htaOfflinehta RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2026-09-29 12:40:146f3f96d13a14b035133bafa3ec817ad5fca970a0ae38d1ca20a89f051beb5d09txt  
2026-09-29 08:20:19beda570aa022ae2a08a2e3647fd50c60cfb1f8827568b2bba669bbac3161bf49htaRemcosRAT