URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: 216.245.184.74
Firstseen:2024-07-12 07:42:05 UTC
Total malware sites :4
Online malware sites :0 (0%)
Offline Malware sites :4 (100%)

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2024-07-12 07:42:08 216.245.184.74Not listedAS399629 BLNWX- USyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2024-07-12 07:43:07http://216.245.184.74/webdav/AmplandSara.exeOfflineexe opendir RemcosRAT ext abuse_ch
2024-07-12 07:42:09http://216.245.184.74/webdav/Windows_Services_A...Offlineexe opendir RemcosRAT ext abuse_ch
2024-07-12 07:42:08http://216.245.184.74/webdav/Windows_Components...Offlineexe opendir Vidar ext abuse_ch
2024-07-12 07:42:08http://216.245.184.74/webdav/Windows_Services_r...Offline7z opendir abuse_ch

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2024-07-12 07:43:07fb1ca952a94f2d19594a44cf7854ed4c957984abf69a16e59a1ac5aeec2a6b60exe RemcosRAT
2024-07-12 07:42:09fb1ca952a94f2d19594a44cf7854ed4c957984abf69a16e59a1ac5aeec2a6b60exe RemcosRAT
2024-07-12 07:42:0830ce4a2a05ae69336192fdea1de4be448bd05e4102d902180bbdb71aca3e934f7z  
2024-07-12 07:42:073ef1d040731916fee2fe1317c53a0e363f05fd12f87b84563af86ac5d49f74c2exeVidar