URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 192.3.193.155
Firstseen:2024-08-07 07:09:04 UTC
Total malware sites :28
Online malware sites :0 (0%)
Offline Malware sites :28 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-08-07 07:09:05 192.3.193.155maze155.mcheap.infoNot listedAS36352 AS-COLOCROSSING- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-09-26 10:41:34http://192.3.193.155/xampp/erg/er/wecreatednewt...OfflineRemcosRAT ext abus3reports
2024-09-26 10:41:34http://192.3.193.155/xampp/erg/WRDF.txtOfflineRemcosRAT ext abus3reports
2024-09-26 10:41:34http://192.3.193.155/xampp/erg/meentireworldthi...OfflineRemcosRAT ext abus3reports
2024-09-21 17:35:40http://192.3.193.155/xampp/mesz/mz/IEnetupdatio...OfflineRemcosRAT ext abus3reports
2024-09-21 17:35:40http://192.3.193.155/xampp/boz/bz/IEnetworkroun...OfflineRemcosRAT ext abus3reports
2024-09-21 17:35:35http://192.3.193.155/xampp/boz/wecreatedbutters...OfflineRemcosRAT ext abus3reports
2024-09-21 17:35:35http://192.3.193.155/xampp/mesz/wethinkchocolat...OfflineRemcosRAT ext abus3reports
2024-08-30 07:41:04http://192.3.193.155/xampp/MM/gemschcoclatecand...Offlinerat RemcosRAT ext abuse_ch
2024-08-30 07:40:07http://192.3.193.155/xampp/MM/mo/IEnetcandy.htaOfflinehta rat RemcosRAT ext abuse_ch
2024-08-29 06:18:07http://192.3.193.155/T2908F/csrss.exeOfflineexe rat RemcosRAT ext abuse_ch
2024-08-29 06:18:06http://192.3.193.155/xampp/gm/IEnetbook.htaOfflinehta rat RemcosRAT ext abuse_ch
2024-08-27 05:40:11http://192.3.193.155/M2608T/csrss.exeOfflineexe RemcosRAT ext abuse_ch
2024-08-27 05:40:06http://192.3.193.155/xampp/meu/createdbeautyinb...OfflineRemcosRAT ext vbs abuse_ch
2024-08-26 17:22:06http://192.3.193.155/xampp/bcg/IEupdation.htaOfflinerat RemcosRAT ext abuse_ch
2024-08-26 06:13:05http://192.3.193.155/xampp/meu/me/iniupdateion.htaOfflinerat RemcosRAT ext abuse_ch
2024-08-21 09:25:08http://192.3.193.155/M1908T/csrss.exeOfflineexe rat RemcosRAT ext abuse_ch
2024-08-21 09:25:08http://192.3.193.155/xampp/uhg/inetcloud.htaOfflinehta rat RemcosRAT ext abuse_ch
2024-08-19 14:08:07http://192.3.193.155/S1808M/csrss.exeOfflineexe rat RemcosRAT ext abuse_ch
2024-08-19 14:08:06http://192.3.193.155/xampp/dmo/netwrking.htaOfflinehta rat RemcosRAT ext abuse_ch
2024-08-13 06:26:07https://192.3.193.155/xampp/gas/GASE.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-08-13 06:26:06https://192.3.193.155/xampp/gas/bss/beseethebut...Offlinedoc RemcosRAT ext NDA0E
2024-08-13 06:26:05https://192.3.193.155/xampp/gas/seethegreatkidm...OfflineRemcosRAT ext vbs NDA0E
2024-08-13 06:25:07http://192.3.193.155/xampp/gas/GASE.txtOfflineascii Encoded RemcosRAT ext rev-base64-loader NDA0E
2024-08-13 06:24:05http://192.3.193.155/xampp/gas/bss/beseethebutt...Offlinedoc RemcosRAT ext NDA0E
2024-08-13 06:24:05http://192.3.193.155/xampp/gas/seethegreatkidma...OfflineRemcosRAT ext vbs NDA0E
2024-08-07 18:45:09http://192.3.193.155/xampp/uhj/GDFG.txtOfflineascii base64 Encoded RemcosRAT ext rev-base64-loader abus3reports
2024-08-07 07:09:05http://192.3.193.155/xampp/uhj/picturegreatfore...Offlinerat RemcosRAT ext abuse_ch
2024-08-07 07:09:05http://192.3.193.155/xampp/uhj/mlm/sincesheisev...Offlinedoc rat RemcosRAT ext abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-08-30 07:40:075e8b58e02bfdbb67a53d6e647e188f5707085fcef0056637ed063ab80fc5235bhta  
2024-08-29 06:18:0752e5414e2e8aabecfc1c38926a3d863e1ee26bef5dc8453fc0568d9f263cf384exeRemcosRAT
2024-08-29 06:18:067d600e1a094b3431567a0608a46b962672c5216e3730d66a55aa4826deca8d78hta RemcosRAT
2024-08-27 05:40:118b2a33314505781855da6824132f4b392cda4eea4862932b1b887673f656338cexeRemcosRAT
2024-08-26 17:22:0699a0f2de32a6c804842d1e0a0370af980f922aa4b5d8be9d4834911891695cebhtaRemcosRAT
2024-08-26 06:13:053ee7cd63e826153e5334bcad95e91de9054286c5503b78ad03febe50eca26853htaRemcosRAT
2024-08-21 09:25:08af9eb52fefdaea155d5129eea96e10a4b99a5538a4ea0f3c9d5c2a926d3d968ehtaRemcosRAT
2024-08-21 09:25:08b833db95708c829952de0ab64c287541fdc039d70d6d5f57ed705c7ee0b435feexe  
2024-08-19 14:08:07ffcfe6a6032cdcef4790afe356d82939369b5e49ba72719b3e592a4de7fd9890exeRemcosRAT
2024-08-19 14:08:06c55f7ab38755b67d90c9f4046f796df881ebfaa89da9204a9cdfc7afa60de44dhtaRemcosRAT
2024-08-13 06:26:0765b5bc63a643d8e0403a3177a6fbcd34db84141682c7c79dae0f91a2a9707c47txt RemcosRAT
2024-08-13 06:26:06bbc54188259e46363f7014000a591e0da5678e477fd48a94091f5adac435ed79rtfRemcosRAT
2024-08-13 06:25:0765b5bc63a643d8e0403a3177a6fbcd34db84141682c7c79dae0f91a2a9707c47txt RemcosRAT
2024-08-13 06:24:05bbc54188259e46363f7014000a591e0da5678e477fd48a94091f5adac435ed79rtfRemcosRAT
2024-08-07 18:45:0965b5bc63a643d8e0403a3177a6fbcd34db84141682c7c79dae0f91a2a9707c47txt RemcosRAT
2024-08-07 07:09:05f2feb32183adb3e808a73617d86f28ba75215da101396bb3ed9354e59eb978e9rtf