URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 185.246.221.98
Firstseen:2022-12-01 15:09:03 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-12-01 15:09:10 185.246.221.98Not listedAS214238 iwihost- BGyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-12-02 00:54:04http://185.246.221.98/321/60E0G7UKRntM1TQ.exeOffline32 exe RemcosRAT ext zbetcheckin
2022-12-01 15:09:10http://185.246.221.98/206/4mi6V9GlgpzpG2X.exeOffline.net exe msil RemcosRAT ext jstrosch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-12-02 00:54:04b5a1e827d96b4c4df1aad8363fe6bd7b4a83ace3f6e15b9689a0f2ddf74c8fb8exeRemcosRAT
2022-12-01 15:09:0447884208f8a644ae2107eecef208a905e03839cb331ccf0dc6c50a72e969b17aexeRemcosRAT