URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 2.58.149.219
Firstseen:2022-04-12 12:03:03 UTC
Total malware sites :19
Online malware sites :0 (0%)
Offline Malware sites :19 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2022-04-12 12:03:06 2.58.149.219Not listedAS212238 CDNEXT- NLyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2022-06-10 09:16:04http://2.58.149.219/EWW.exeOfflineexe NanoCore ext rat abuse_ch
2022-06-03 09:01:04http://2.58.149.219/WAU.exeOffline32 AgentTesla ext exe zbetcheckin
2022-05-24 13:40:04http://2.58.149.219/MMS.exeOffline32 exe NanoCore ext zbetcheckin
2022-05-24 12:51:04http://2.58.149.219/XUY.exeOfflineNanoCore ext James_inthe_box
2022-05-19 13:45:05http://2.58.149.219/HOU.exeOfflineexe rat RemcosRAT ext abuse_ch
2022-05-10 11:21:04http://2.58.149.219/asa.exeOffline32 exe RemcosRAT ext zbetcheckin
2022-05-10 11:07:04http://2.58.149.219/WCY.exeOffline32 AgentTesla ext exe zbetcheckin
2022-05-10 06:54:03http://2.58.149.219/wvi.exeOffline32 AgentTesla ext exe zbetcheckin
2022-05-10 05:37:03http://2.58.149.219/hfe.exeOffline32 exe RemcosRAT ext zbetcheckin
2022-05-10 05:30:05http://2.58.149.219/ESP.exeOffline32 exe NanoCore ext zbetcheckin
2022-05-10 05:19:04http://2.58.149.219/XTY.exeOffline32 exe NanoCore ext zbetcheckin
2022-04-28 06:43:05http://2.58.149.219/AXD.exeOfflineexe rat RemcosRAT ext abuse_ch
2022-04-27 09:31:04http://2.58.149.219/CBZ.exeOfflineexe rat RemcosRAT ext abuse_ch
2022-04-14 10:27:03http://2.58.149.219/AOY.exeOfflineexe rat RemcosRAT ext abuse_ch
2022-04-13 07:24:04http://2.58.149.219/file/Fpctpjc_Jbcodntq.pngOfflineencrypted rat RemcosRAT ext abuse_ch
2022-04-12 12:03:10http://2.58.149.219/file/Jppxlhz_Itxaqmwg.jpgOfflineAgentTesla ext encrypted abuse_ch
2022-04-12 12:03:10http://2.58.149.219/file/Tbtqglzcu_Oawpyxvi.pngOfflineencrypted rat RemcosRAT ext abuse_ch
2022-04-12 12:03:06http://2.58.149.219/AWC.exeOfflineexe rat RemcosRAT ext abuse_ch
2022-04-12 12:03:06http://2.58.149.219/CTC.exeOfflineAgentTesla ext exe abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2022-06-10 09:16:0437f06a03ca9d8ac7c86ee2b3d7e6ee399aa56b9356caf00f802021f9247ac70fexeNanoCore
2022-06-03 09:01:043f0da0c03ce3305ae5fdc9d58b9dc4b8ab209abbd75743472440d21899c6167bexeAgentTesla
2022-06-01 11:49:2578c21b763279fb9cd065137aae3fc8f21cf1846492799df0baf0155c4a60789aexeNanoCore
2022-05-24 13:40:04d84c58ea7491dd341d6d5616f6ee21f2cf1d1b9d49b5624a15c82071ed5c61b5exeNanoCore
2022-05-24 12:51:04dc5a63b06f0be5f96267b2ebfe28a4e7644de021cce402dd666f7454233bd96bexeNanoCore
2022-05-19 13:45:0517f5cb1dba8dd540465e9135d6541f2a7f871caee59c8afc63cf17e820c0f22fexeRemcosRAT
2022-05-10 11:21:042873e1ab0b1bf260f4d8bfeb50a6305036bfb9b8aed7c1e4f227484a8fdd4862exeRemcosRAT
2022-05-10 11:07:04e46d797785ee0837fbe4f643f1f8bfe3331306c3b46b2505b72e2e562b6b8525exeAgentTesla
2022-05-10 06:54:03e365bf7a715adc7c10d91e2961c5a43a6831a85d93980c56e580f81d1239adbfexeAgentTesla
2022-05-10 05:37:0322fef69204d216970d72ecfcbf27fd0634ed03271bbe5c486c02fda6daeb51dfexeRemcosRAT
2022-05-10 05:30:05e8ee83f88ca4002f3705768b89c154e280e7b30ec022ae9ee54988c9499a9560exeNanoCore
2022-05-10 05:19:0463a0aaadde3fc67e75ade5ec3840257a47981567fbc9870b30726fa93efe6a63exeNanoCore
2022-04-28 06:43:05721d0deb1e187d8bfabb4e8e08d78e931a316a298c0675301d6bb539e5e57f68exeRemcosRAT
2022-04-27 09:31:04bc4cee107dc86c0b272beea0bf170d2908082689bad99e57e695c9cea006dac6exeRemcosRAT
2022-04-14 10:27:031b2ff2a125694851ba8469c670bc5d3a741d67a62f3c0d12704ee6c6b161c688exeRemcosRAT
2022-04-13 07:24:046d777034f043b8febf6c15f1a850ded27cb493ddcb11a9b8a2e5f16303ab4f2cunknown  
2022-04-12 12:03:10a1bbc8bd2ee5837acf4a0a11d03439f3c0c03434ffa3e7a48889eceb48f2a4e9unknown  
2022-04-12 12:03:10e6c4794b3deab23262e1356289134384c105a52b700ce63645b22580792545a7unknown  
2022-04-12 12:03:05902f4adc25817f82a216b60a7658cb9a267e877ea0197d69cc279fc02ba4906dexeRemcosRAT
2022-04-12 12:03:05a4cafd75b158468af748409a3cdac4f5245f74cbfea052cc4052f6d6a526cc73exeAgentTesla