URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.3.176.154
Firstseen:2024-07-26 12:55:05 UTC
Total malware sites :18
Online malware sites :0 (0%)
Offline Malware sites :18 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-07-26 12:55:07 192.3.176.154192-3-176-154-host.colocrossing.comNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-08-01 11:27:07https://192.3.176.154/900/MMM.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-08-01 11:27:07https://192.3.176.154/700/BNHH.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-08-01 11:27:05https://192.3.176.154/900/smo/xxx.docOfflinedoc RemcosRAT ext NDA0E
2024-08-01 08:38:06http://192.3.176.154/900/MMM.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-07-31 07:54:05http://192.3.176.154/900/smo/xxx.docOfflinedoc rat RemcosRAT ext abuse_ch
2024-07-31 07:54:04http://192.3.176.154/900/buttersmoothflowerways...Offlinerat RemcosRAT ext vbs abuse_ch
2024-07-30 19:14:06http://192.3.176.154/700/BNHH.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-07-30 18:08:05http://192.3.176.154/700/hgn/iamworkingonentire...Offlinedoc RemcosRAT ext abuse_ch
2024-07-30 18:08:04http://192.3.176.154/700/beautifulthingsherehap...Offlinerat RemcosRAT ext vbs abuse_ch
2024-07-27 06:04:06http://192.3.176.154/46/winiti.exeOffline32 exe Formbook ext zbetcheckin
2024-07-26 13:46:07http://192.3.176.154/50/HNBC.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-07-26 13:45:11https://192.3.176.154/50/HNBC.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-07-26 13:40:08https://192.3.176.154/xampp/glo/KBV.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-07-26 13:39:08http://192.3.176.154/xampp/glo/KBV.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-07-26 12:56:05http://192.3.176.154/xampp/glo/gl/funtogetbackt...Offlinedoc RemcosRAT ext NDA0E
2024-07-26 12:56:04http://192.3.176.154/xampp/glo/createactiveimag...OfflineRemcosRAT ext vbs NDA0E
2024-07-26 12:55:07http://192.3.176.154/50/screensimplethingstohan...OfflineRemcosRAT ext vbs NDA0E
2024-07-26 12:55:07http://192.3.176.154/50/BNC/iamtotalnewpersonto...Offlinedoc RemcosRAT ext NDA0E

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-08-01 11:27:0745e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055txt RemcosRAT
2024-08-01 11:27:0745e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055txt RemcosRAT
2024-08-01 11:27:0549d137f7f8521f2fcde3f3e94a14fbe32210baf3f15522383c5e59016c641f7brtfRemcosRAT
2024-08-01 08:38:0645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055txt RemcosRAT
2024-07-31 09:35:3049d137f7f8521f2fcde3f3e94a14fbe32210baf3f15522383c5e59016c641f7brtfRemcosRAT
2024-07-31 07:54:057cb995c84cad428dd2183e8ca94d7b07cdb154d8a5fdc23ab50cc6ff72fa1af7rtfRemcosRAT
2024-07-30 19:14:0645e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055txt RemcosRAT
2024-07-30 18:08:0580129fee40e59865743b9070328bc42c237aeb4c8162cc9ca9f87755c68e9356rtfRemcosRAT
2024-07-27 06:04:06dc46b790c20e5077fc05879616e9d87acfdec0b4d2e2d9e82e5ce666487fdfafexeFormbook
2024-07-26 13:46:0745e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055txt RemcosRAT
2024-07-26 13:45:1145e30715396b41ed298fc2fc05d94f3a962536daa72f2c5d72e7d784323a4055txt RemcosRAT
2024-07-26 13:40:08c8336cb6887f0bbe0b12744f5c43638979603a57a5fc96eb7f34015fb312b4f7txt RemcosRAT
2024-07-26 13:39:08c8336cb6887f0bbe0b12744f5c43638979603a57a5fc96eb7f34015fb312b4f7txt RemcosRAT
2024-07-26 12:56:0525210bf101e90b41547334124d89da300d74672054e6aefaa89aac51e55c1e10rtfRemcosRAT
2024-07-26 12:55:07a0a088ddefea91b081ce3eef407d62a9ebbab95b010c23d4afcbaed4896ea61frtfRemcosRAT